« Volver al listado

CVE-2026-22991

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

libceph: make free_choose_arg_map() resilient to partial allocation

free_choose_arg_map() may dereference a NULL pointer if its caller fails after a partial allocation.

For example, in decode_choose_args(), if allocation of arg_map->args fails, execution jumps to the fail label and free_choose_arg_map() is called. Since arg_map->size is updated to a non-zero value before memory allocation, free_choose_arg_map() will iterate over arg_map->args and dereference a NULL pointer.

To prevent this potential NULL pointer dereference and make free_choose_arg_map() more resilient, add checks for pointers before iterating.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-22991",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-22991",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-16T20:35:31.087945Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "9b3730dabcf3764bfe3ff07caf55e641a0b45234",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "851241d3f78a5505224dc21c03d8692f530256b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "ec1850f663da64842614c86b20fe734be070c2ba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "8081faaf089db5280c3be820948469f7c58ef8dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "c4c2152a858c0ce4d2bff6ca8c1d5b0ef9f2cbdf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "f21c3fdb96833aac2f533506899fe38c19cf49d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cf9c4a9959b6273675310d14a834ef14fbca37c",
              "lessThan": "e3fe30e57649c551757a02e1cad073c47e1e075e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ceph/osdmap.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.248",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.198",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.161",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.121",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.66",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.6",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ceph/osdmap.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-01-23T16:15:55.183",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/8081faaf089db5280c3be820948469f7c58ef8dd",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/851241d3f78a5505224dc21c03d8692f530256b4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b3730dabcf3764bfe3ff07caf55e641a0b45234",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4c2152a858c0ce4d2bff6ca8c1d5b0ef9f2cbdf",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3fe30e57649c551757a02e1cad073c47e1e075e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec1850f663da64842614c86b20fe734be070c2ba",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f21c3fdb96833aac2f533506899fe38c19cf49d5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: make free_choose_arg_map() resilient to partial allocation\n\nfree_choose_arg_map() may dereference a NULL pointer if its caller fails\nafter a partial allocation.\n\nFor example, in decode_choose_args(), if allocation of arg_map->args\nfails, execution jumps to the fail label and free_choose_arg_map() is\ncalled. Since arg_map->size is updated to a non-zero value before memory\nallocation, free_choose_arg_map() will iterate over arg_map->args and\ndereference a NULL pointer.\n\nTo prevent this potential NULL pointer dereference and make\nfree_choose_arg_map() more resilient, add checks for pointers before\niterating."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nlibceph: hacer free_choose_arg_map() resistente a la asignación parcial\n\nfree_choose_arg_map() puede desreferenciar un puntero NULL si su llamador falla después de una asignación parcial.\n\nPor ejemplo, en decode_choose_args(), si la asignación de arg_map->args falla, la ejecución salta a la etiqueta fail y se llama a free_choose_arg_map(). Dado que arg_map->size se actualiza a un valor distinto de cero antes de la asignación de memoria, free_choose_arg_map() iterará sobre arg_map->args y desreferenciará un puntero NULL.\n\nPara evitar esta potencial desreferencia de puntero NULL y hacer free_choose_arg_map() más resistente, añadir comprobaciones para los punteros antes de iterar."
    }
  ],
  "lastModified": "2026-06-17T10:20:39.907",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14DEF845-E647-4A78-9311-A8F1A59E3A66",
              "versionEndExcluding": "5.10.248",
              "versionStartIncluding": "4.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82159CAA-B6BA-43C6-85D8-65BDBC175A7E",
              "versionEndExcluding": "5.15.198",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E135B7E2-61FC-4DC1-8570-ABD67894FFDE",
              "versionEndExcluding": "6.1.161",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB7A164B-7422-4A1C-82FB-5FCAEE53C06C",
              "versionEndExcluding": "6.6.121",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F72B884C-B44F-40E4-9895-CE421AC663D0",
              "versionEndExcluding": "6.12.66",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "879529BC-5B4C-4EBE-BF1D-1A31404A8B2E",
              "versionEndExcluding": "6.18.6",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17B67AA7-40D6-4AFA-8459-F200F3D7CFD1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C47E4CC9-C826-4FA9-B014-7FE3D9B318B2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F71D92C0-C023-48BD-B3B6-70B638EEE298"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13580667-0A98-40CC-B29F-D12790B91BDB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}