CVE-2025-68284

Linux Kernel Out-of-Bounds Write in libceph handle_auth_session_key()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() The len field originates from untrusted network packets. Boundary checks have been added to prevent potential out-of-bounds writes when decrypting the connection secret or processing service tickets. [ idryomov: changelog ]

Scores

EPSS 0.0008
EPSS Percentile 22.7%

Details

Status published
Products (19)
linux/Kernel 5.11.0 - 5.15.197linux
linux/Kernel 5.16.0 - 6.1.159linux
linux/Kernel 6.13.0 - 6.17.11linux
linux/Kernel 6.2.0 - 6.6.119linux
linux/Kernel 6.7.0 - 6.12.61linux
Linux/Linux < 5.11
Linux/Linux 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 - 5ef575834ca99f719d7573cdece9df2fe2b72424
Linux/Linux 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 - 6920ff09bf911bc919cd7a6b7176fbdd1a6e6850
Linux/Linux 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 - 7fce830ecd0a0256590ee37eb65a39cbad3d64fc
Linux/Linux 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 - 8dfcc56af28cffb8f25fb9be37b3acc61f2a3d09
... and 9 more
Published Dec 16, 2025
Tracked Since Feb 18, 2026