In the Linux kernel, the following vulnerability has been resolved:
libceph: define and enforce CEPH_MAX_KEY_LEN
When decoding the key, verify that the key material would fit into
a fixed-size buffer in process_auth_done() and generally has a sane
length.
The new CEPH_MAX_KEY_LEN check replaces the existing check for a key
with no key material which is a) not universal since CEPH_CRYPTO_NONE
has to be excluded and b) doesn't provide much value since a smaller
than needed key is just as invalid as no key -- this has to be handled
elsewhere anyway.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-08 14:16
Updated : 2026-06-17 10:49
NVD link : CVE-2026-43304
Mitre link : CVE-2026-43304
CVE.ORG link : CVE-2026-43304
JSON object : View
Products Affected
linux
- linux_kernel
CWE
