Multiple vulnerabilities in Ceph (20 August 2026)
Multiple vulnerabilities have been discovered in Ceph. They allow an attacker to cause privilege escalation, breach of data confidentiality and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities in Ceph permit privilege escalation, confidentiality breach, and security policy bypass.
- Who is affected
- All Ceph deployments are potentially affected; specific versions not stated.
- Urgency
- Moderate urgency due to privilege escalation and data confidentiality impact, though no active exploitation reported.
- Action
- Check Ceph security advisories for affected versions and apply patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Ceph
Get an email when a new Ceph advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1057/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-39944 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54330 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-30156 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50152 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Ceph
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()msrc · 2026-08-11
- mediumCVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZEmsrc · 2026-08-11
- criticalCVE-2026-68160: In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-…nvd · 2026-08-10
- criticalCVE-2026-68159: In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,up…nvd · 2026-08-10
- criticalCVE-2026-68158: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplicatio…nvd · 2026-08-10
- criticalCVE-2026-68156: In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->aut…nvd · 2026-08-10
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21