CVE-2025-68283
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68283 is a bounds-checking vulnerability in the Linux kernel's libceph component where OSD (Object Storage Daemon) indexes derived from untrusted network packets were not validated against map->max_osd. The flaw stems from the use of BUG_ON assertions instead of proper boundary checks, which could be triggered by malformed network data. It was published on December 16, 2025, and affects Linux kernel versions across multiple stable branches (6.1.x, 6.6.x, 6.12.x, 6.17.x, and 6.18). Microsoft also identified it as affecting the Azure Linux 3 kernel package azl3_kernel_6.6.117.1-1. The CVSS v3.1 base score is 7.1 (High) (Feedly, Microsoft MSRC).

Technical details

The root cause is improper input validation (CWE-20) in the libceph kernel subsystem, where OSD index values received from network packets were used without being checked against the upper bound map->max_osd. This could lead to out-of-bounds memory access. The fix replaces unsafe BUG_ON assertions — which cause an immediate kernel panic — with proper bounds checks that gracefully handle invalid index values; the BUG_ON in ceph_get_primary_affinity() was also removed as part of the patch. Exploitation requires local access with low privileges, as an attacker would need to influence or craft network packets containing invalid OSD indexes that are processed by the Ceph client (Feedly, Microsoft MSRC).

Impact

Successful exploitation could result in kernel denial of service (system crash or hang) or potential data corruption in the Ceph filesystem component, impacting both integrity and availability. An attacker with local, low-privileged access who can influence Ceph OSD network traffic could trigger out-of-bounds memory access in the kernel. Confidentiality is not directly impacted, but system instability or data corruption on Ceph-backed storage could have significant operational consequences in environments relying on Ceph for distributed storage (Feedly).

Mitigation and workarounds

Patches are available across all affected Linux kernel stable branches. Administrators should update to the following minimum versions: 6.1.159 (for 6.1.x), 6.6.119 (for 6.6.x), 6.12.61 (for 6.12.x), 6.17.11 (for 6.17.x), or any 6.18 release with the fix applied. Debian LTS, Ubuntu (USN-8094-1 through USN-8094-5, USN-8152-1), SUSE, and Oracle Linux have all issued updated kernel packages. As a compensating control, restrict local user access on systems running Ceph clients and monitor for unexpected kernel crashes or system instability (Feedly, Ubuntu USN-8094-1, Debian LTS).

Community reactions

The vulnerability received routine coverage from Linux distribution security teams, with Debian, Ubuntu, SUSE, and Oracle Linux all issuing advisories and updated kernel packages. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and scanner detection updates from Qualys and Tenable (Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management