ReviewCritical

CVE-2026-80558

Linux

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create the up and acting set in ceph_pg_to_up_acting_osds(), called from calc_target(). While most of these osd indices are checked, the one from primary_temp is not. Subsequently, this may lead to calc_tar...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.27
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create the up and acting set in ceph_pg_to_up_acting_osds(), called from calc_target(). While most of these osd indices are checked, the one from primary_temp is not. Subsequently, this may lead to calc_tar...

Affected product and versions

Product
Linux
Affected versions
>= 5e8d4d36bf23bb7baf027c479d54395840219928 < 505fc50b8ff8e687b7e3ef6866269dea27366224, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < 1c705fe8e59c6b16f48964973fb23c8ec4735b73, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < dfe1877d351b99eb1b1a62a3fc2d174220e88e20, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < e2ffeec85201b2bb748e99e12539ee1b92f62796, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < 6799d4a916ffcb3d450d8440f9fe0f0862f768d6, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < 4f392fec075562dc93bb0c69f37423ca2af9b48f, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < e009c5f0ad634c62f5c48a41f1f3c019ecf52555, >= 5e8d4d36bf23bb7baf027c479d54395840219928 < 3660b98d1204b419f6a77e9a295f148dcf38d042, >= 3.15
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available