CVE-2026-46024
Published: May 27, 2026
Modified: Jun 1, 2026
CVSS v3.1
7.5
Description
In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treated as an error. In case of ac->negotiating == true and ac->protocol > 0, this leads to setting ac->protocol = 0 and ac->ops = NULL. Thereafter, the check for ac->protocol != protocol returns false, and init_protocol() is not called. Subsequently, ac->ops->handle_reply() is called, which leads to a null pointer dereference, because ac->ops is still NULL. This patch changes the check for ac->protocol != protocol to !ac->protocol, as this also includes the case when the protocol was set to zero in the message. This causes the message to be treated as containing a bad auth protocol.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 9ded62c302c0342efdb5eda3bf6e75720caad0dfaffected 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < f101271fcf55d7eacfefd610b51ec65f46ba8118affected 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 4b2738b93edad661178340239de657d876b73d3daffected 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 927e4bd5692f2a4901808822981fb2c8d4456548affected 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc - < 016bc663657366d386993f63eb31072eb45a2b77+2 more versions |
Linux | Linux | affected 2.6.34unaffected 0 - < 2.6.34unaffected 5.15.209 - <= 5.15.*unaffected 6.1.175 - <= 6.1.*unaffected 6.6.140 - <= 6.6.*+4 more versions |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now