You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2025 68283
About this tag
CVE-2025-68283 is a Linux kernel vulnerability in the Ceph client library (libceph) that was patched in December 2025. The fix replaces dangerous BUG_ON assertions with proper bounds checks to prevent out-of-bounds access from untrusted OSD indexes in network packets. This vulnerability could lead to memory corruption or denial-of-service in systems processing malicious Ceph map updates. The patch specifically addresses code paths in ceph_get_primary_affinity and related functions, adding explicit checks against map->max_osd. The vulnerability is classified as important-to-moderate by vendors. This tag covers discussions about the CVE-2025-68283 kernel fix, its impact on Ceph storage systems, and the defensive coding changes made to improve security.
A quiet but consequential fix landed in the Linux kernel tree on December 16, 2025: a defensive coding change in the Ceph client library (libceph) replaced several fatal assertions with proper bounds checks to block untrusted OSD indexes from network packets — a change recorded as CVE-2025-68283...