CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in cephhandlecaps()
cephhandlecaps() reads snaptracelen from the wire-format cephmdscaps header and uses it unconditionally to build a fake end pointer (snaptrace + snaptracelen) that is later handed to cephupdatesnaptrace() in the CEPHCAPOPIMPORT case:
snaptrace = h + 1; snaptracelen = le32tocpu(h->snaptracelen); p = snaptrace + snaptracelen; ... case CEPHCAPOPIMPORT: if (snaptracelen) { ... if (cephupdatesnaptrace(mdsc, snaptrace, snaptrace + snaptracelen, false, &realm)) { ... }
cephupdatesnaptrace() then decodes a struct cephmdssnaprealm from snaptrace using cephdecodeneed(&p, e, sizeof(ri), bad) with the attacker-supplied fake end e == snaptrace + snaptracelen. With snaptracelen == 0xFFFFFFFF the bound check is trivially satisfied, ri = p reads sizeof(struct cephmdssnaprealm) past the legitimate msg->front buffer, and ri->numsnaps / ri->numpriorparentsnaps then drive further out-of-bounds reads of the encoded snap arrays.
The eleven msgversion >= 2 .. msgversion >= 12 decoder blocks above the op switch each catch this OOB through their cephdecodesafe() / cephdecodeneed() helpers, but they sit behind a hdr.version-gated if, so a malicious or compromised MDS that sets msg->hdr.version = 1 reaches the IMPORT path with no version-gated decoder having validated snaptracelen. The shape has been present since cephhandlecaps() was introduced.
Validate snaptracelen against the message front buffer before consuming it, using the canonical cephdecodeneed() / cephhasroom() helper. The helper bounds the length with subtraction (n <= end - p, guarded by end >= p) rather than pointer addition, so it is wrap-safe for the attacker-controlled u32 length on 32-bit builds where p + snaptracelen could overflow the address space. This matches the rest of the ceph decode path (e.g. the poolnslen check a few lines below), and the existing goto bad cleanup already covers this exit path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68160?
CVE-2026-68160 has a risk score of 47, indicating a medium severity vulnerability.
How do I fix CVE-2026-68160?
To fix CVE-2026-68160, ensure that your Linux kernel is updated to the latest patched version that addresses this vulnerability.
What vulnerabilities does CVE-2026-68160 address?
CVE-2026-68160 addresses a pre-authentication out-of-bounds read vulnerability in the ceph_handle_caps() function.
What systems are affected by CVE-2026-68160?
CVE-2026-68160 affects configurations of the Linux kernel that utilize the Ceph distributed file system.
When was CVE-2026-68160 published?
CVE-2026-68160 was published on August 10, 2026.