CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode()
Published Jun 24, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
21 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.143.1-1
Linux Linux kernel>=2.6.34.1<5.10.258
Linux Linux kernel>=5.11<5.15.209
Linux Linux kernel>=5.16<6.1.175
Linux Linux kernel>=6.2<6.6.141
Linux Linux kernel>=6.7<6.12.91
Linux Linux kernel>=6.13<6.18.33
Linux Linux kernel>=6.19<7.0.10
Linux Linux kernel=2.6.34
Linux Linux kernel=2.6.34-rc2
Linux Linux kernel=2.6.34-rc3
Linux Linux kernel=2.6.34-rc4
Linux Linux kernel=2.6.34-rc5
Linux Linux kernel=2.6.34-rc6
Linux Linux kernel=2.6.34-rc7
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
debian/linux<=5.10.223-1
5.10.262-16.1.176-16.1.180-16.12.94-16.12.101-17.1.8-27.1.10-1
debian/linux-6.1
6.1.180-1~deb11u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-2Fixed in 7.1.10-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.180-1~deb11u1
Event History
Jun 24, 2026
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:06 PM
DescriptionSeverityAffected Software
Jun 27, 2026
Data Sourced
via Microsoft·08:19 AM
DescriptionSeverityWeaknessAffected Software
Aug 12, 2026
Data Sourced
via Launchpad·08:39 PM
Description
Aug 25, 2026
Data Sourced
via Debian·12:34 AM
DescriptionAffected Software
Aug 26, 2026
Data Sourced
via Ubuntu·12:33 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-52955?
CVE-2026-52955 has a risk score of 34, indicating a moderate severity level.
2
How do I fix CVE-2026-52955?
To mitigate CVE-2026-52955, update to the latest version of the Linux kernel where the vulnerability has been patched.
3
What is the impact of CVE-2026-52955?
CVE-2026-52955 could potentially allow for out-of-bounds access which may lead to memory corruption.
4
In which component is CVE-2026-52955 found?
CVE-2026-52955 is found in the libceph component of the Linux kernel.
5
When was CVE-2026-52955 published?
CVE-2026-52955 was published on June 24, 2026.