CVE-2026-68433
Last modified
CVE-2026-68433 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read. Use msg->front.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire..
Description
In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read. Use msg->front.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 513a8243d67f8e8d27f2883bd2f18bc87c7ca376, < 340e0386aa39da181015bee38f309018c335ce16; >= 513a8243d67f8e8d27f2883bd2f18bc87c7ca376, < d60de8253c85a02d0e6194b0735e7a562981a04c; >= 513a8243d67f8e8d27f2883bd2f18bc87c7ca376, < 4e7ebfaa0d14cf50e44041bfde38070d6dbc019f; >= 513a8243d67f8e8d27f2883bd2f18bc87c7ca376, < 0d934c934ec746d53fc7e4f53239792647bbae63; >= 513a8243d67f8e8d27f2883bd2f18bc87c7ca376, < d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 |
| Linux | Linux | 3.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68433?
How severe is CVE-2026-68433?
How do I fix CVE-2026-68433?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68428In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68429In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6843A flaw was found in nano. A local user could exploit a forma…5.5
- CVE-2026-68430In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68431In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68432In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68434In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68435In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68436In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68437In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68438In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68439In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
