ThreatCluster

CVE-2026-22992 and CVE-2026-22984 Address libceph Vulnerabilities

First seen 28 Feb 2026, 10:11 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in the libceph component have been identified: CVE-2026-22992, which involves returning the handler error from mon_handle_auth_done(), and CVE-2026-22984, which prevents potential out-of-bounds reads in handle_auth_done(). Both vulnerabilities were published on January 23, 2026, affecting systems utilizing the libceph library.

Timeline

2026-01-23
CVE-2026-22992 published
2026-01-23
CVE-2026-22984 published
2026-02-28
Information published about CVE-2026-22992
2026-02-28
Information published about CVE-2026-22984