CVE-2026-68433 is a vulnerability in Linux Kernel
Published on August 12, 2026
libceph: bound get_version reply decode to front len
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound get_version reply decode to front len
handle_get_version_reply() uses msg->front_alloc_len as the decode
boundary for MON_GET_VERSION_REPLY. That is the size of the reused
reply buffer, not the number of bytes actually received.
A truncated reply can therefore pass ceph_decode_need() and decode the
second u64 from stale tail bytes left in the buffer by an earlier
message, causing an uninitialized memory read.
Use msg->front.iov_len as the receive-side decode boundary, matching
other libceph reply handlers and limiting decoding to the bytes that
were actually read from the wire.
Products Associated with CVE-2026-68433
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 and below 340e0386aa39da181015bee38f309018c335ce16 is affected.
- Version 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 and below d60de8253c85a02d0e6194b0735e7a562981a04c is affected.
- Version 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 and below 4e7ebfaa0d14cf50e44041bfde38070d6dbc019f is affected.
- Version 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 and below 0d934c934ec746d53fc7e4f53239792647bbae63 is affected.
- Version 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 and below d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 is affected.
- Version 3.16 is affected.
- Before 3.16 is unaffected.
- Version 6.6.148, <= 6.6.* is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc5, <= * is unaffected.