Linuxカーネルにおいて、以下の脆弱性が修正されました。libcephのcrush_decode()における潜在的な範囲外アクセスの問題です。crushマップを含む少なくとも1つのバケットを持つCEPH_MSG_OSD_MAPタイプのメッセージには、バケットアルゴリズムを保持する2つのフィールドがあります。これら2つのフィールドの値が異なる場合、範囲外アクセスが発生する可能性があります。これは、最初のアルゴリズムフィールド(alg)がこのタイプのバケットに対して適切なメモリ量を割り当てるために使用される一方で、バケット内の2番目のアルゴリズムフィールド(b->alg)が後続の処理で使用されるためです。このパッチは、algとb->algを比較し、異なる場合は処理を中断するチェックを追加することで問題を修正します。さらに、b->algはこの場合に0に設定されます。これは破棄時にcrushマップがこのフィールドを用いてバケットタイプを判別しており、そうしないとバケットのフィールドが指すメモリを解放する際に再度範囲外アクセスが発生する可能性があるためです。こうした場合にバケットに割り当てられたメモリを正しく解放するために、対応するkfreeの呼び出しはアルゴリズム固有のcrush_destroy_bucket関数からジェネリックなcrush_destroy_bucket()関数へ移動されました。
Linux Linux Kernel 2.6.34.1 以上 5.10.258 未満 Linux Kernel 5.11 以上 5.15.209 未満 Linux Kernel 5.16 以上 6.1.175 未満 Linux Kernel 6.13 以上 6.18.33 未満 Linux Kernel 6.19 以上 7.0.10 未満 Linux Kernel 6.2 以上 6.6.141 未満 Linux Kernel 6.7 以上 6.12.91 未満 Linux Kernel 2.6.34 Linux Kernel 7.1
本脆弱性の影響を受ける製品の詳細については、ベンダ情報および参考情報をご確認ください。
・当該ソフトウェアが扱う情報について、外部への漏えいは発生しません。 ・当該ソフトウェアが扱う情報について、書き換えは発生しません。 ・当該ソフトウェアが完全に停止する可能性があります。
ベンダ情報を参照して適切な対策を実施してください。
レッドハット Red Hat : https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52955.json Red Hat Bugzilla : 2492328 (CVE-2026-52955) CVE-2026-52955 kernel: libceph: Fix potential out-of-bounds access in crush_decode() Red Hat Customer Portal : CVE-2026-52955 - Red Hat Customer Portal
境界外読み取り(CWE-125) [NVD評価] バッファサイズの計算の誤り(CWE-131) [その他]
CVE-2026-52955
National Vulnerability Database (NVD) : CVE-2026-52955 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/fb176a99e4c1a5a8448a83d83d3606203ba81faa) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/3f42508191e129ee6b5ea96578d5cab14f2a013a) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/4c79fc2d598694bda845b46229c9d48b65042970) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/6e70ef53e818c53eab28d7b0026b7fd03dddaba5) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/0f3604cbe4df14c5e58288ac9f57511e726a222d) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ea0d42137f0c06da71e37ffc647aab4c5309599a) 関連文書 : libceph: Fix potential out-of-bounds access in crush_decode() - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ebe76d58a48a48031b98543d86c4cd30a825b622)
[2026年07月16日] 掲載