CVE-2026-46024
In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treated as an error. In case of ac-negotiating == true and ac-protocol > 0, this leads to setting ac-protocol = 0 and ac-ops = NULL. Thereafter, the check for ac-protocol != protocol returns false, and init_protocol() is not called.
Subsequently, ac-ops-handle_reply() is called, which leads to a null pointer dereference, because ac-ops is still NULL. This patch changes the check for ac-protocol != protocol to !ac-protocol, as this also includes the case when the protocol was set to zero in the message. This causes the message to be treated as containing a bad auth protocol.
- CVSS base score ≥ 7.0
ATT&CK techniques
1Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniques