CVE-2026-68154
Last modified
CVE-2026-68154 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper..
Description
In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229, < b8a9fb6bf806f9c4891e71ae1beab0c07c23a877; >= f24e9980eb860d8600cbe5ef3d2fd9295320d229, < 826cd1de5802fd392922785f9b64d76e65d2a100; >= f24e9980eb860d8600cbe5ef3d2fd9295320d229, < 3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56; >= f24e9980eb860d8600cbe5ef3d2fd9295320d229, < 70998f91030ee083ecb336a1dff0701c20a38081; >= f24e9980eb860d8600cbe5ef3d2fd9295320d229, < 05f90284223381005d6bcddab3fda4a97f9c3401 |
| Linux | Linux | 2.6.34 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68154?
How severe is CVE-2026-68154?
How do I fix CVE-2026-68154?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68149In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6815An arbitrary file write vulnerability exists in Casdoor's Lo…5.9
- CVE-2026-68150In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68151In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68152In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68153In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68155In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68156In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68157In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68158In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68159In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6816An access bypass vulnerability in Drupal TFA Basic Plugins a…3.8
Are you affected by CVE-2026-68154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
