What is CVE-2026-68082?
CVE-2026-68082 is a vulnerability in the Linux kernel's libceph component where two bare decode operations in the `decode_lockers()` function allow a malicious OSD to trigger slab-out-of-bounds reads. Affected systems should apply the relevant security patch to mitigate potential exploits.
Azərbaycanca: Linux kernel-də libceph komponentində aşkar edilmiş CVE-2026-68082 zəifliyi `decode_lockers()` funksiyasındakı iki `bare decode` əməliyyatı ilə bağlıdır. Bu, zərərli OSD-nin `slab-out-of-bounds` oxuma hücumlarına səbəb olmasına imkan yaradır. Təsirə məruz qalan sistemlərdə təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which component of the Linux kernel is affected by CVE-2026-68082?
CVE-2026-68082 affects the libceph component of the Linux kernel.
How can a malicious OSD exploit CVE-2026-68082?
A malicious OSD can trigger slab-out-of-bounds reads via two bare decode operations in the `decode_lockers()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.