libceph: reset sparse-read state in osd_fault()
Published Feb 14, 2026
7.6
HIGHCVSS 3.1
EPSS 0.30%
Description
When a fault occurs, the connection is abandoned, reestablished, and any pending operations are retried. The OSD client tracks the progress of a sparse-read reply using a separate state machine, largely independent of the messenger's state.
If a connection is lost mid-payload or the sparse-read state machine returns an error, the sparse-read state is not reset. The OSD client will then interpret the beginning of a new reply as the continuation of the old one. If this makes the sparse-read machinery enter a failure state, it may never recover, producing loops like:
libceph: [0] got 0 extents libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read
Therefore, reset the sparse-read state in osd_fault(), ensuring retries start from a clean state.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.6StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.6
- Version 6.12.66StatusunaffectedConstraints<=6.12.*
- Version 6.18.6StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version 6.6.121StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.6 · < 6.6.121
- ≥ 6.7 · < 6.12.66
- ≥ 6.13 · < 6.18.6
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10.0 Extended Update Support
kernel-0:6.12.0-55.82.1.el10_0
Fixed · RHSA-2026:27731
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.54.1.el9_7
Fixed · RHSA-2026:13565
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.54.1.el9_7
Fixed · RHSA-2026:13565
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.10.1.el9_8
Fixed · RHSA-2026:19568
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.10.1.el9_8
Fixed · RHSA-2026:19568
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.123.1.el9_6
Fixed · RHSA-2026:27708
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10.0 Extended Update Support | kernel-0:6.12.0-55.82.1.el10_0 | Fixed | RHSA-2026:27731 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.54.1.el9_7 | Fixed | RHSA-2026:13565 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.54.1.el9_7 | Fixed | RHSA-2026:13565 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.10.1.el9_8 | Fixed | RHSA-2026:19568 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.10.1.el9_8 | Fixed | RHSA-2026:19568 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.123.1.el9_6 | Fixed | RHSA-2026:27708 |
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A reliability and availability issue exists in the libceph OSD client sparse read handling. The client tracks progress of a sparse read reply using a separate state machine. When a connection fault happens mid payload or when the sparse read state machine returns an error, the connection is abandoned and later reestablished and pending operations are retried. However the sparse read state was not reset on the fault path. As a result the client can misinterpret the beginning of a new reply as a continuation of the previous reply. This can drive the sparse read machinery into a persistent failure mode that may never recover, producing repeated error messages and repeated socket read failures, effectively preventing successful reads and causing continuous retry loops. From a threat perspective the trigger can be a misbehaving or compromised Ceph OSD server, or a network adversary able to disrupt or truncate traffic, causing fault and retry sequences. The primary impact is denial of service for Ceph clients performing sparse reads.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-23136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439852 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5901 Advisory
- https://git.kernel.org/stable/c/10b7c72810364226f7b27916ea3e2a4f870bc04b Patch
- https://git.kernel.org/stable/c/11194b416ef95012c2cfe5f546d71af07b639e93 Patch
- https://git.kernel.org/stable/c/90a60fe61908afa0eaf7f8fcf1421b9b50e5f7ff Patch
- https://git.kernel.org/stable/c/e94075e950a6598e710b9f7dffea5aa388f40313 Patch
- https://lore.kernel.org/linux-cve-announce/2026021428-CVE-2026-23136-f28c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-23136
- https://www.cve.org/CVERecord?id=CVE-2026-23136
Change history (0)
No recorded changes yet.