CVE-2026-68158Network attack vector

Kernel-memory disclosure via overflowing OSD map length

Published Aug 10, 2026 · Updated Aug 10, 2026

Out-of-bounds read in affected Linux kernel versions allows remote attackers to read kernel memory via a corrupted CEPH_MSG_OSD_MAP. decode_new_up_state_weight() multiplies a message-supplied item count to size the new_state bounds check; integer wraparound makes the check accept a too-short buffer. Exposure requires libceph to accept an attacker-controlled OSD map; consequences are kernel-memory disclosure or a system crash.

CVSS severity9.8
Critical
EPSS probability0.70%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Out-of-bounds read in affected Linux kernel versions allows remote attackers to read kernel memory via a corrupted CEPH_MSG_OSD_MAP. decode_new_up_state_weight() multiplies a message-supplied item count to size the new_state bounds check; integer wraparound makes the check accept a too-short buffer. Exposure requires libceph to accept an attacker-controlled OSD map; consequences are kernel-memory disclosure or a system crash.

The record

CVE
CVE-2026-68158
Published
Aug 10, 2026
Updated
Aug 10, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-125
Attack vector
network
Privileges
unauthenticated

Timeline

How it unfolded

  1. Aug 10, 2026CVE publishedPublication date reported by the CVE source.
  2. Aug 10, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=032951d32c13b7564dfba82758260cb7aa1149d2
  2. Affected versionversion=1196c36fd53c3b1615eb02f986cb727b1dfc1047
  3. Affected versionversion=14877928f10667a5606383885d004f7185f33718
  4. Affected versionversion=3.10.103 <3.11
  5. Affected versionversion=3.12.63 <3.13
  6. Affected versionversion=3.14.75 <3.15
  7. Affected versionversion=3.16.39 <3.17
  8. Affected versionversion=3.18.39 <3.19
  9. Affected versionversion=4.1.30 <4.2
  10. Affected versionversion=4.4.17 <4.5
  11. Affected versionversion=4.6.6 <4.7
  12. Affected versionversion=4.7
  13. Affected versionversion=6831c98ce0b8a3e88db64aa224372effd0dcc694
  14. Affected versionversion=6b96b2d473701b45df3fea8dd9796b6ec39e6d54
  15. Affected versionversion=7405d73cea0d0e6c541f5c534078feeb46188844
  16. Affected versionversion=8777c9f654637d56f4c4ca54eb1bc7c609b70085
  17. Affected versionversion=930c532869774ebf8af9efe9484c597f896a7d46 <05c90e059269f087becfcce23348496085835c29
  18. Affected versionversion=930c532869774ebf8af9efe9484c597f896a7d46 <143ba49ead77ec483c0326f8aaad8649874e99c4
  19. Affected versionversion=930c532869774ebf8af9efe9484c597f896a7d46 <1732d89dfcd74f6fde9ce70900d316c4a151c153
  20. Affected versionversion=930c532869774ebf8af9efe9484c597f896a7d46 <98917a499ec7064c14fc56d180a4fd636fc2784c
  21. Affected versionversion=930c532869774ebf8af9efe9484c597f896a7d46 <bee4b5b53e7bff0467fd916cc44c9b190733c6bd
  22. Affected versionversion=bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196

What conditions does exploitation require?

Attack vectornetwork
Required privilegesunauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=032951d32c13b7564dfba82758260cb7aa1149d2; version=1196c36fd53c3b1615eb02f986cb727b1dfc1047; version=14877928f10667a5606383885d004f7185f33718; version=3.10.103 <3.11; version=3.12.63 <3.13; version=3.14.75 <3.15; version=3.16.39 <3.17; version=3.18.39 <3.19; version=4.1.30 <4.2; version=4.4.17 <4.5; version=4.6.6 <4.7; version=4.7; version=6831c98ce0b8a3e88db64aa224372effd0dcc694; version=6b96b2d473701b45df3fea8dd9796b6ec39e6d54; version=7405d73cea0d0e6c541f5c534078feeb46188844; version=8777c9f654637d56f4c4ca54eb1bc7c609b70085; version=930c532869774ebf8af9efe9484c597f896a7d46 <05c90e059269f087becfcce23348496085835c29; version=930c532869774ebf8af9efe9484c597f896a7d46 <143ba49ead77ec483c0326f8aaad8649874e99c4; version=930c532869774ebf8af9efe9484c597f896a7d46 <1732d89dfcd74f6fde9ce70900d316c4a151c153; version=930c532869774ebf8af9efe9484c597f896a7d46 <98917a499ec7064c14fc56d180a4fd636fc2784c; version=930c532869774ebf8af9efe9484c597f896a7d46 <bee4b5b53e7bff0467fd916cc44c9b190733c6bd; version=bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196

Published CVSS scores

7.0Red HatCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
9.8cve.orgCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectornetwork
Privilegesunauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-125Out-of-bounds Read

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo