{"id":"OESA-2026-3531","summary":"kernel security update","details":"The Linux Kernel, the operating system core itself.\r\n\r\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n    snaptrace     = h + 1;\n    snaptrace_len = le32_to_cpu(h-&gt;snap_trace_len);\n    p             = snaptrace + snaptrace_len;\n    ...\n    case CEPH_CAP_OP_IMPORT:\n        if (snaptrace_len) {\n            ...\n            if (ceph_update_snap_trace(mdsc, snaptrace,\n                                       snaptrace + snaptrace_len,\n                                       false, &amp;realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(&amp;p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg-&gt;front buffer, and ri-&gt;num_snaps /\nri-&gt;num_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version &gt;= 2 .. msg_version &gt;= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg-&gt;hdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper.  The helper bounds the length with subtraction (n &lt;= end - p,\nguarded by end &gt;= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space.  This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath.(CVE-2026-68160)","modified":"2026-08-30T04:31:34.425322271Z","published":"2026-08-30T04:15:03Z","upstream":["CVE-2026-68160"],"database_specific":{"severity":"Critical"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3531"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68160"}],"affected":[{"package":{"name":"kernel","ecosystem":"openEuler:20.03-LTS-SP4","purl":"pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.19.90-2608.5.0.0387.oe2003sp4"}]}],"ecosystem_specific":{"src":["kernel-4.19.90-2608.5.0.0387.oe2003sp4.src.rpm"],"x86_64":["bpftool-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","bpftool-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-debugsource-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-devel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-source-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-tools-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-tools-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","kernel-tools-devel-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","python2-perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","python2-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","python3-perf-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm","python3-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.x86_64.rpm"],"aarch64":["bpftool-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","bpftool-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-debugsource-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-devel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-source-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-tools-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-tools-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","kernel-tools-devel-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","python2-perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","python2-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","python3-perf-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm","python3-perf-debuginfo-4.19.90-2608.5.0.0387.oe2003sp4.aarch64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3531.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}