CVE-2026-22984: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit bounds check on payload_len to avoid a possible out-of-bounds access in the callout. [ idryomov: changelog ]

Affected products

  • Linux Linux Kernel: from 5.11, before 5.15.198 (fixed in 5.15.198); from 5.16, before 6.1.161 (fixed in 6.1.161); from 6.2, before 6.6.121 (fixed in 6.6.121); from 6.7, before 6.12.66 (fixed in 6.12.66); from 6.13, before 6.18.6 (fixed in 6.18.6); version 6.19 only

Published 2026-01-23. Last modified 2026-06-17.