<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ceph - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ceph/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 10:37:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ceph/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-68160: Out-of-Bounds Read in Ceph ceph_handle_caps</title><link>https://feed.craftedsignal.io/briefs/2026-08-ceph-oob-read/</link><pubDate>Tue, 11 Aug 2026 10:37:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ceph-oob-read/</guid><description>A vulnerability in the Ceph ceph_handle_caps function allows for an out-of-bounds read during the pre-authentication phase, potentially leading to denial-of-service or memory disclosure.</description><content:encoded><![CDATA[<p>CVE-2026-68160 identifies an out-of-bounds read vulnerability within the Ceph storage system, specifically located in the ceph_handle_caps() function. The flaw occurs during the pre-authentication phase when processing snaptrace data. An attacker capable of interacting with the Ceph service during this early handshake stage could trigger the vulnerability. If successfully exploited, this defect may result in a denial-of-service condition due to application crashes or potentially lead to the disclosure of sensitive memory contents residing in the affected memory regions. This vulnerability is relevant to security operations teams monitoring Ceph storage clusters for unauthorized or malformed pre-authentication traffic.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could result in service instability, causing the Ceph daemon to crash, or the unauthorized access to sensitive memory. This poses a risk to organizations relying on Ceph for high-availability storage, as it could be used to disrupt data access or leak information from memory buffers.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Ceph installations to the latest patched version provided by the Ceph project or distribution maintainers.</li>
<li>Review network access control lists (ACLs) to restrict unauthorized access to Ceph services, especially if exposed to untrusted networks.</li>
<li>Monitor logs for repeated service crashes of the Ceph daemon, which may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>ceph</category><category>memory-safety</category></item></channel></rss>