Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 63

Количество 63

fstec логотип

BDU:2026-11423

11 месяцев назад

Уязвимость функции have_mon_and_osd_map() компонента net/ceph/ceph_common.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2025-68285

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70 Read of size 4...

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-68285

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70 Read of size 4...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2025-68285

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-68285

9 месяцев назад

libceph: fix potential use-after-free in have_mon_and_osd_map()

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2025-68285

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: l ...

CVSS3: 9.8
EPSS: Низкий
rocky логотип

RLSA-2026:0786

8 месяцев назад

Important: kernel security update

EPSS: Низкий
github логотип

GHSA-v24j-9ghx-7rf2

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_...

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-0786

8 месяцев назад

ELSA-2026-0786: kernel security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1045-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5)

EPSS: Низкий
rocky логотип

RLSA-2026:0444

8 месяцев назад

Important: kernel security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0444

8 месяцев назад

ELSA-2026-0444: kernel security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1102-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0945-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7 RT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0755

7 месяцев назад

ELSA-2026-0755: kernel security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2026:0793

8 месяцев назад

Important: kernel security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0793

8 месяцев назад

ELSA-2026-0793: kernel security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1136-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 15 SP7)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1100-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0967-1

6 месяцев назад

Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-11423

Уязвимость функции have_mon_and_osd_map() компонента net/ceph/ceph_common.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
1%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-68285

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70 Read of size 4...

CVSS3: 9.8
1%
Низкий
9 месяцев назад
redhat логотип
CVE-2025-68285

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon_and_osd_map+0x56/0x70 Read of size 4...

CVSS3: 5.5
1%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-68285

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_mon

CVSS3: 9.8
1%
Низкий
9 месяцев назад
msrc логотип
CVE-2025-68285

libceph: fix potential use-after-free in have_mon_and_osd_map()

CVSS3: 7.8
1%
Низкий
9 месяцев назад
debian логотип
CVE-2025-68285

In the Linux kernel, the following vulnerability has been resolved: l ...

CVSS3: 9.8
1%
Низкий
9 месяцев назад
rocky логотип
RLSA-2026:0786

Important: kernel security update

1%
Низкий
8 месяцев назад
github логотип
GHSA-v24j-9ghx-7rf2

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_map() and handle_one_map() install a new map immediately after freeing the old one kfree(monc->monmap); monc->monmap = monmap; ceph_osdmap_destroy(osdc->osdmap); osdc->osdmap = newmap; under client->monc.mutex and client->osdc.lock respectively, but because neither is taken in have_mon_and_osd_map() it's possible for client->monc.monmap->epoch and client->osdc.osdmap->epoch arms in client->monc.monmap && client->monc.monmap->epoch && client->osdc.osdmap && client->osdc.osdmap->epoch; condition to dereference an already freed map. This happens to be reproducible with generic/395 and generic/397 with KASAN enabled: BUG: KASAN: slab-use-after-free in have_...

CVSS3: 9.8
1%
Низкий
9 месяцев назад
oracle-oval логотип
ELSA-2026-0786

ELSA-2026-0786: kernel security update (IMPORTANT)

1%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1045-1

Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5)

6 месяцев назад
rocky логотип
RLSA-2026:0444

Important: kernel security update

8 месяцев назад
oracle-oval логотип
ELSA-2026-0444

ELSA-2026-0444: kernel security update (IMPORTANT)

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1102-1

Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7)

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0945-1

Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7 RT)

6 месяцев назад
oracle-oval логотип
ELSA-2026-0755

ELSA-2026-0755: kernel security update (MODERATE)

7 месяцев назад
rocky логотип
RLSA-2026:0793

Important: kernel security update

8 месяцев назад
oracle-oval логотип
ELSA-2026-0793

ELSA-2026-0793: kernel security update (IMPORTANT)

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1136-1

Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 15 SP7)

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1100-1

Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6)

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0967-1

Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5)

6 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.