PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90067 Linux CVE debrief

A vulnerability in the Linux kernel's Ceph messenger v2 protocol implementation can cause a 0-length socket read when a client sends a banner with an invalid payload length, triggering a warning and potentially leading to a protocol error. The issue has been resolved by adding a check to reject payload lengths smaller than 16 bytes. This vulnerability affects Linux kernel versions and could lead to protocol errors if exploited. Defenders should assess exposure and prioritize patching, particularly in environments using Ceph. The CVE record and associated sources provide details on the vulnerability, including its description, CVSS score, and affected components.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for Linux kernel security, particularly in environments using Ceph, should assess exposure and prioritize patching. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review and update Ceph configurations to ensure secure protocol implementation. They should also monitor for potential protocol errors and warnings in kernel logs, and perform vulnerability scanning toidentify

Why it matters

A vulnerability in the Linux kernel's Ceph messenger v2 protocol implementation can cause a 0-length socket read when a client sends a banner with an invalid payload length, triggering a warning and potentially leading to a protocol error.

  • Verify and prioritize patching for Linux kernel versions affected by this vulnerability
  • Review and update Ceph configurations to ensure secure protocol implementation
  • Monitor for potential protocol errors and warnings in kernel logs

Technical summary

The Linux kernel's Ceph messenger v2 protocol implementation is vulnerable to a 0-length socket read when a client sends a banner with an invalid payload length. This issue has been resolved by adding a check to reject payload lengths smaller than 16 bytes. The vulnerability affects Linux kernel versions and could lead to protocol errors if exploited. Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly in environments using Ceph. The fix prevents the 0-length read and correctly aborts the connection with a protocol error.

Defensive priority

Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly in environments using Ceph.

Recommended defensive actions

  • Verify and apply patches for Linux kernel versions affected by this vulnerability
  • Review and update Ceph configurations to ensure secure protocol implementation
  • Monitor for potential protocol errors and warnings in kernel logs
  • Perform vulnerability scanning to identify affected systems
  • Implement compensating controls for exposed systems
  • Review asset inventory for affected components
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and associated sources provide details on the vulnerability, including its description, CVSS score, and affected components. However, specific version information and exploitation details are not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90067 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90067

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90067 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90067

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/279c0852999fd2384f4a88155091a99e81f96873

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3b2e62a7655d347a845a91155610ddae11daffc6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6cf666e47f2b51d5a887ec8a3226cde951757d27

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6d1c6f228854aa89844fd0152d7ed7ac72a55e89

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c1b937ff24b19e69aa7fb1b0f46a74d4c9668692

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c77633a9595658210a6e216a071e5a396a0835a7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f374967fcdf04001c9b66df1c19106fa83cd91f7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.