← All CVEs

CVE-2026-43304

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buffer in process_auth_done() and generally has a sane length. The new CEPH_MAX_KEY_LEN check replaces the existing check for a key with no key material which is a) not universal since CEPH_CRYPTO_NONE has to be excluded and b) doesn't provide much value since a smaller than needed key is just as invalid as no key -- this has to be handled elsewhere anyway.

9.8
CVSS
0.5%
EPSS (exploit prob.)
42nd
EPSS percentile
2026-05-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 5.11, < 5.15.202
linuxlinux_kernel>= 5.16, < 6.1.165
linuxlinux_kernel>= 6.2, < 6.6.128
linuxlinux_kernel>= 6.7, < 6.12.75
linuxlinux_kernel>= 6.13, < 6.18.16
linuxlinux_kernel>= 6.19, < 6.19.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-43304