Security advisory #39

Information

State: published
Published at: 2026-08-23 09:45:13 CEST
CVEs: CVE-2026-68154
Name: libceph zero CRUSH bucket type
Summary: English: Denial of service
Česky: Odepření služby
Description: English: A VPS administrator can mount CephFS from a cluster they control because the deployed container setup permits CephFS mounts from a VPS. A malicious cluster can supply a CRUSH map with a bucket type reserved for devices, causing the kernel client to index the OSD weight array with a negative value. The resulting out-of-bounds kernel read does not directly provide root inside the VPS. The reviewed technical evidence does not establish a path to root on the node or access to another VPS. An invalid read may crash the shared kernel and affect node availability.
Česky: Správce VPS může připojit CephFS z clusteru, který ovládá, protože nasazené nastavení kontejnerů připojení CephFS z VPS umožňuje. Škodlivý cluster může dodat mapu CRUSH s typem bucketu vyhrazeným pro zařízení, což přiměje klienta v jádře indexovat pole vah OSD zápornou hodnotou. Výsledné čtení mimo hranice paměti jádra samo o sobě nezajistí root uvnitř VPS. Analyzované technické podklady nepopisují postup k získání root na node ani k přístupu do jiného VPS. Neplatné čtení může shodit sdílené jádro a ovlivnit dostupnost node.
Response: English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.3. The Ceph client now rejects the reserved zero bucket type while decoding a CRUSH map. Upstream Linux includes the fix in 6.12.101 and later stable releases.
Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.3. Klient Ceph nyní při dekódování mapy CRUSH odmítne vyhrazený nulový typ bucketu. Ve stabilních vydáních Linuxu je oprava obsažena od verze 6.12.101.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-09 05:15:09 CEST 2026-08-09 05:15:39 CEST
node20.prg mitigated 2026-08-09 05:15:20 CEST 2026-08-09 05:15:50 CEST
node21.prg mitigated 2026-08-09 05:15:24 CEST 2026-08-09 05:15:54 CEST
node22.prg mitigated 2026-08-09 05:15:05 CEST 2026-08-09 05:15:35 CEST
node23.prg mitigated 2026-08-09 05:15:51 CEST 2026-08-09 05:16:21 CEST
node24.prg mitigated 2026-08-09 05:15:25 CEST 2026-08-09 05:15:55 CEST
node25.prg mitigated 2026-08-09 05:15:09 CEST 2026-08-09 05:15:39 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-09 05:00:50 CEST 2026-08-09 05:01:20 CEST
node1.pgnd mitigated 2026-08-09 13:47:43 CEST 2026-08-09 13:48:13 CEST
node1.stg mitigated 2026-08-07 19:28:40 CEST 2026-08-07 19:29:10 CEST
node2.stg mitigated 2026-08-07 19:28:40 CEST 2026-08-07 19:29:10 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791