{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/ceph/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68160"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ceph"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","ceph","memory-safety"],"_cs_type":"advisory","_cs_vendors":["Ceph"],"content_html":"\u003cp\u003eCVE-2026-68160 identifies an out-of-bounds read vulnerability within the Ceph storage system, specifically located in the ceph_handle_caps() function. The flaw occurs during the pre-authentication phase when processing snaptrace data. An attacker capable of interacting with the Ceph service during this early handshake stage could trigger the vulnerability. If successfully exploited, this defect may result in a denial-of-service condition due to application crashes or potentially lead to the disclosure of sensitive memory contents residing in the affected memory regions. This vulnerability is relevant to security operations teams monitoring Ceph storage clusters for unauthorized or malformed pre-authentication traffic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in service instability, causing the Ceph daemon to crash, or the unauthorized access to sensitive memory. This poses a risk to organizations relying on Ceph for high-availability storage, as it could be used to disrupt data access or leak information from memory buffers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Ceph installations to the latest patched version provided by the Ceph project or distribution maintainers.\u003c/li\u003e\n\u003cli\u003eReview network access control lists (ACLs) to restrict unauthorized access to Ceph services, especially if exposed to untrusted networks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated service crashes of the Ceph daemon, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T10:37:04Z","date_published":"2026-08-11T10:37:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ceph-oob-read/","summary":"A vulnerability in the Ceph ceph_handle_caps function allows for an out-of-bounds read during the pre-authentication phase, potentially leading to denial-of-service or memory disclosure.","title":"CVE-2026-68160: Out-of-Bounds Read in Ceph ceph_handle_caps","url":"https://feed.craftedsignal.io/briefs/2026-08-ceph-oob-read/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68082"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libceph"],"_cs_severities":["medium"],"_cs_tags":["memory-corruption","vulnerability","libceph","storage","memory-safety","linux","ceph"],"_cs_type":"threat","_cs_vendors":["Ceph"],"content_html":"\u003cp\u003eMicrosoft has disclosed CVE-2026-68082, involving two instances of unsafe bare decodes within the decode_lockers() function of the libceph library. These vulnerabilities stem from improper handling of data during the deserialization process of incoming network traffic. When a Ceph component processes specially crafted network input, these unsafe decoding operations can lead to memory safety violations, potentially resulting in memory corruption, process crashes, or other undefined behavior within the Ceph infrastructure. Organizations utilizing Ceph storage clusters should review their dependency versions and apply security updates provided by the Ceph project to remediate these deserialization flaws.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in memory corruption within the libceph library, potentially leading to denial of service through process termination or the corruption of internal memory structures. The impact is primarily focused on storage environments relying on libceph for data handling and management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of the libceph library across all storage infrastructure components to the version containing the fix for CVE-2026-68082. Use software composition analysis (SCA) tools to inventory the use of libceph within existing applications and container images.\u003c/p\u003e\n","date_modified":"2026-08-11T10:36:09Z","date_published":"2026-08-09T09:36:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-libceph-unsafe-decodes/","summary":"CVE-2026-68082 describes two unsafe bare decode operations within the libceph decode_lockers() function that could lead to memory corruption during network data deserialization.","title":"Memory Safety Vulnerability in libceph decode_lockers()","url":"https://feed.craftedsignal.io/briefs/2026-08-libceph-unsafe-decodes/"}],"language":"en","title":"CraftedSignal Threat Feed - Ceph","version":"https://jsonfeed.org/version/1.1"}