---
id: CVE-2026-52962
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ceph: fix a buffer leak in __ceph_setxattr()

  The old_blob in __ceph_setxattr() can store
  ci->i_xattrs.prealloc_blob value during the retry.
  However, it is never called…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ceph: fix a buffer leak in __ceph_setxattr()

  The old_blob in __ceph_setxattr() can store
  ci->i_xattrs.prealloc_blob value during the retry.
  However, it is never called…
severity: none
published: '2026-06-24'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52962'
references:
  - url: 'https://git.kernel.org/stable/c/3fa13ceefbc5f36131110342743994cb3de80637'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4bfdcefdaa6092a06cacd59389c7756b36e6de8c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/521e5aba857fd267624892c8dd6295f22ce0267e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5d3cc36b4e77a27ce7b686b7c59c7072bcb3fa8e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7d3e8d2d648d5f0df29b4710246680f47695fe94'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc7abce4460e490dcb579eec770f175b150b685f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d0cb994605c84a159c1d00d72cdc8583c321ef95'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ecf94823c5c6a20790bb76ed2816822b0beb0c22'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00176
epssPercentile: 0.06295
ingestedAt: '2026-06-29T13:42:11.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix a buffer leak in __ceph_setxattr()

The old_blob in __ceph_setxattr() can store
ci->i_xattrs.prealloc_blob value during the retry.
However, it is never called the ceph_buffer_put()
for the old_blob object. This patch fixes the issue of
the buffer leak.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
