CVE-2026-43273

Source
https://cve.org/CVERecord?id=CVE-2026-43273
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43273.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43273
Downstream
Published
2026-05-06T11:28:56.851Z
Modified
2026-05-28T03:54:31.363358501Z
Summary
ceph: supply snapshot context in ceph_zero_partial_object()
Details

In the Linux kernel, the following vulnerability has been resolved:

ceph: supply snapshot context in cephzeropartial_object()

The cephzeropartial_object function was missing proper snapshot context for its OSD write operations, which could lead to data inconsistencies in snapshots.

Reproducer: ../src/vstart.sh --new -x --localhost --bluestore ./bin/ceph auth caps client.fsa mds 'allow rwps fsname=a' mon 'allow r fsname=a' osd 'allow rw tag cephfs data=a' mount -t ceph fsa@.a=/ /mnt/mycephfs/ -o conf=./ceph.conf dd if=/dev/urandom of=/mnt/mycephfs/foo bs=64K count=1 mkdir /mnt/mycephfs/.snap/snap1 md5sum /mnt/mycephfs/.snap/snap1/foo fallocate -p -o 0 -l 4096 /mnt/mycephfs/foo echo 3 > /proc/sys/vm/drop/caches md5sum /mnt/mycephfs/.snap/snap1/foo # get different md5sum!!

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43273.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ad7a60de882aca31afb58721db166f7e77afcd92
Fixed
36673344b41c31fb502dd0d0113cec1aa96f581e
Fixed
5788b742007f53406049bef917833a71ddd43f60
Fixed
757873abfc8ea38592582180aed0f57f0f0cb07a
Fixed
9efa154609cdb658f51c7d76b30a09f7e6485250
Fixed
531a76c5a2e44264cee8a70121e63eb28c1ba728
Fixed
69e59a87bab0ea31ab2a584fc65e12dafacf8953
Fixed
4097e70fc543cca72982854108a32f6ae924e727
Fixed
f16bd3fa74a2084ee7e16a8a2be7e7399b970907

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43273.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
5.10.252
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.202
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.165
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.128
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.75
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43273.json"