Linuxカーネルにおいて、以下の脆弱性が修正されました。libcephのceph_handle_auth_reply()関数における潜在的なヌルポインタ参照を防止する対応が行われました。CEPH_MSG_AUTH_REPLYタイプのメッセージで、protocolおよびresultがともに0の値を持つ場合、現在はエラーとみなされていません。ac-negotiatingがtrueかつac-protocolが0より大きい場合、ac-protocolを0に、ac-opsをNULLに設定します。その後、ac-protocol != protocolのチェックはfalseとなり、init_protocol()は呼ばれません。その結果、ac-ops-handle_reply()が呼ばれ、ヌルポインタ参照が発生します。このパッチではac-protocol != protocolのチェックを!ac-protocolに変更し、メッセージでprotocolが0に設定されている場合も不正な認証プロトコルとして扱うようにしました。
Linux Linux Kernel 2.6.34.1 以上 5.15.209 未満 Linux Kernel 5.16 以上 6.1.175 未満 Linux Kernel 6.13 以上 6.18.27 未満 Linux Kernel 6.19 以上 7.0.4 未満 Linux Kernel 6.2 以上 6.6.140 未満 Linux Kernel 6.7 以上 6.12.86 未満 Linux Kernel 2.6.34
・当該ソフトウェアが扱う情報について、外部への漏えいは発生しません。 ・当該ソフトウェアが扱う情報について、書き換えは発生しません。 ・当該ソフトウェアが完全に停止する可能性があります。
リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
NULL ポインタデリファレンス(CWE-476) [NVD評価]
CVE-2026-46024
National Vulnerability Database (NVD) : CVE-2026-46024 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/4b2738b93edad661178340239de657d876b73d3d) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/927e4bd5692f2a4901808822981fb2c8d4456548) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/5199c125d25aeae8615c4fc31652cc0fe624338e) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/8f2be7285941a33a9f72579a23b96392f83c758e) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/016bc663657366d386993f63eb31072eb45a2b77) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/9ded62c302c0342efdb5eda3bf6e75720caad0df) 関連文書 : libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/f101271fcf55d7eacfefd610b51ec65f46ba8118)
[2026年06月17日] 掲載