{"schema_version":"1.7.5","id":"CVE-2026-22984","published":"2026-01-23T15:24:06.245Z","modified":"2026-07-15T01:49:19.545144471Z","related":["ALSA-2026:19568","ALSA-2026:25120","ALSA-2026:25121","SUSE-SU-2026:0447-1","SUSE-SU-2026:0472-1","SUSE-SU-2026:0587-1","SUSE-SU-2026:20477-1","SUSE-SU-2026:20498-1","SUSE-SU-2026:20555-1","SUSE-SU-2026:20570-1","SUSE-SU-2026:20599-1","SUSE-SU-2026:20615-1","SUSE-SU-2026:20845-1","SUSE-SU-2026:20876-1","openSUSE-SU-2026:20287-1"],"summary":"libceph: prevent potential out-of-bounds reads in handle_auth_done()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: prevent potential out-of-bounds reads in handle_auth_done()\n\nPerform an explicit bounds check on payload_len to avoid a possible\nout-of-bounds access in the callout.\n\n[ idryomov: changelog ]","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"cd1a677cad994021b19665ed476aea63f5d54f31"},{"fixed":"194cfe2af4d2a1de599d39dad636b47c2f6c2c96"},{"fixed":"79fe3511db416d2f2edcfd93569807cb02736e5e"},{"fixed":"ef208ea331ef688729f64089b895ed1b49e842e3"},{"fixed":"2802ef3380fa8c4a08cda51ec1f085b1a712e9e2"},{"fixed":"2d653bb63d598ae4b096dd678744bdcc34ee89e8"},{"fixed":"818156caffbf55cb4d368f9c3cac64e458fb49c9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22984.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.198"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.161"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.121"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.66"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22984.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/194cfe2af4d2a1de599d39dad636b47c2f6c2c96"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2802ef3380fa8c4a08cda51ec1f085b1a712e9e2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2d653bb63d598ae4b096dd678744bdcc34ee89e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79fe3511db416d2f2edcfd93569807cb02736e5e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/818156caffbf55cb4d368f9c3cac64e458fb49c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ef208ea331ef688729f64089b895ed1b49e842e3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22984.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22984"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22984.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}