Review reviewHigh

CVE-2026-52954

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded...

CVSS
7.5
EPSS
0.52%
41.4% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.52%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 5cf9c4a9959b6273675310d14a834ef14fbca37c < c7bf7864e2924fa5508ac270b0e9364bc13d5a6c, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < f47430fc1f815e87406e2d3b4e476eff1bc7fd9b, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < 0b6a3bcb91bc5bfeda39f0df3b71bab62c13e9da, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < 534ebc08df97c47d4c7596f336fa31ecbf91519c, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < 80c73bd1b2b04355d1d0c29be8ccbd25a380905d, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < 4d2b37abda9536808655830d683dc491d31741a8, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < 0a1265a9ab875f92b6a3ffb497404f46cf9d76a3, >= 5cf9c4a9959b6273675310d14a834ef14fbca37c < d289478cfc0bcf81c7914200d6abdcb78bd04ded, >= 4.13, >= 4.13 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10, 7.1
Fixed versions
5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-617
CVE-2026-52954 — Linux Linux, linux kernel | SECUFOCUS NOW