CVE Database
/

CVE-2026-46024

Back to search

CVE-2026-46024

Published: May 27, 2026

Modified: Jun 1, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treated as an error. In case of ac->negotiating == true and ac->protocol > 0, this leads to setting ac->protocol = 0 and ac->ops = NULL. Thereafter, the check for ac->protocol != protocol returns false, and init_protocol() is not called. Subsequently, ac->ops->handle_reply() is called, which leads to a null pointer dereference, because ac->ops is still NULL. This patch changes the check for ac->protocol != protocol to !ac->protocol, as this also includes the case when the protocol was set to zero in the message. This causes the message to be treated as containing a bad auth protocol.

VendorProductVersions

Linux

Linux

affected
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 9ded62c302c0342efdb5eda3bf6e75720caad0df
affected
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < f101271fcf55d7eacfefd610b51ec65f46ba8118
affected
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 4b2738b93edad661178340239de657d876b73d3d
affected
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 927e4bd5692f2a4901808822981fb2c8d4456548
affected
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 016bc663657366d386993f63eb31072eb45a2b77

+2 more versions

Linux

Linux

affected
2.6.34
unaffected
0 - < 2.6.34
unaffected
5.15.209 - <= 5.15.*
unaffected
6.1.175 - <= 6.1.*
unaffected
6.6.140 - <= 6.6.*

+4 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-46024 | HIGH (7.5) - Security Vulnerability | QwikSec