CVE-2026-22990: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted such that the incremental osdmap epoch is different from what is expected, there is no need to BUG. Instead, just declare the incremental osdmap to be invalid.
Affected products
- Linux Linux Kernel: from 2.6.34.1, before 5.10.248 (fixed in 5.10.248); from 5.11, before 5.15.198 (fixed in 5.15.198); from 5.16, before 6.1.161 (fixed in 6.1.161); from 6.2, before 6.6.121 (fixed in 6.6.121); from 6.7, before 6.12.66 (fixed in 6.12.66); from 6.13, before 6.18.6 (fixed in 6.18.6); …
Published 2026-01-23. Last modified 2026-06-17.