OESA-2026-3531

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3531
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3531.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2026-3531
Upstream
Published
2026-08-30T04:15:03Z
Modified
2026-08-30T04:31:34Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
kernel security update
Details

The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()

ceph_handle_caps() reads snap_trace_len from the wire-format ceph_mds_caps header and uses it unconditionally to build a fake end pointer (snaptrace + snaptrace_len) that is later handed to ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:

snaptrace     = h + 1;
snaptrace_len = le32_to_cpu(h->snap_trace_len);
p             = snaptrace + snaptrace_len;
...
case CEPH_CAP_OP_IMPORT:
    if (snaptrace_len) {
        ...
        if (ceph_update_snap_trace(mdsc, snaptrace,
                                   snaptrace + snaptrace_len,
                                   false, &realm)) { ... }

ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm from snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad) with the attacker-supplied fake end e == snaptrace + snaptrace_len. With snaptrace_len == 0xFFFFFFFF the bound check is trivially satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past the legitimate msg->front buffer, and ri->num_snaps / ri->num_prior_parent_snaps then drive further out-of-bounds reads of the encoded snap arrays.

The eleven msg_version >= 2 .. msg_version >= 12 decoder blocks above the op switch each catch this OOB through their ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit behind a hdr.version-gated if, so a malicious or compromised MDS that sets msg->hdr.version = 1 reaches the IMPORT path with no version-gated decoder having validated snap_trace_len. The shape has been present since ceph_handle_caps() was introduced.

Validate snap_trace_len against the message front buffer before consuming it, using the canonical ceph_decode_need() / ceph_has_room() helper. The helper bounds the length with subtraction (n <= end - p, guarded by end >= p) rather than pointer addition, so it is wrap-safe for the attacker-controlled u32 length on 32-bit builds where p + snap_trace_len could overflow the address space. This matches the rest of the ceph decode path (e.g. the pool_ns_len check a few lines below), and the existing goto bad cleanup already covers this exit path.(CVE-2026-68160)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2608.5.0.0387.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "bpftool-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-debugsource-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-devel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-source-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-tools-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "python2-perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "python3-perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "kernel-4.19.90-2608.5.0.0387.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "bpftool-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-debugsource-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-devel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-source-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-tools-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "python2-perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "python3-perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3531.json"