Structured the bug description with the canonical SRU template.
The regression blocks all kernel rbd mappings on Ubuntu 24.04 when Ceph
clusters enforce AES-256 CephX keys following CVE-2025-30156 fixes in
ceph-common.
The attached kernel patch bumps CEPH_MAX_KEY_LEN to 32 (matching
mainline Linux) and was verified locally on 6.8.0-134.
** Description changed:
+ [ Impact ]
+
+ On Ubuntu 24.04 LTS (Noble) with the 6.8 kernel series, kernel-based
+ Ceph clients (such as rbd block device mappings, ceph-fuse, and cephfs
+ kernel mounts) fail to map or mount storage when connecting to Ceph
+ clusters using updated userspace packages (ceph-common 19.2.6+ or
+ 20.2.4+):
+
+ $ rbd map rbd/pool1
+ rbd: failed to add secret 'client.admin' to kernel
+ In some cases useful info is found in syslog - try "dmesg | tail".
+ rbd: map failed: (22) Invalid argument
+
+ The kernel rejects the CephX authentication key and logs an error in
+ dmesg:
+
+ [345785.965860] libceph: secret too big 32
+
+ This regression was triggered by CVE-2025-30156 remediation. Ceph
+ userspace transitioned to 256-bit AES keys (32 bytes) for CephX
+ authentication, but the Linux 6.8 libceph module enforces a hardcoded
+ limit of CEPH_MAX_KEY_LEN = 16, resulting in a total operational failure
+ for all kernel Ceph storage mappings in Ubuntu 24.04.
+
+ [ Fix ]
+
+ In net/ceph/crypto.h, bump CEPH_MAX_KEY_LEN from 16 to 32 bytes:
+
+ #define CEPH_MAX_KEY_LEN 32
+
+ And in net/ceph/crypto.c, include the maximum allowed length in the
+ diagnostic output:
+
+ pr_err("secret too big %d (max %d)\n", key->len, CEPH_MAX_KEY_LEN);
+
+ The kernel crypto subsystem (cbc(aes)) already natively supports 256-bit
+ (32-byte) AES keys. Mainline Linux already defines CEPH_MAX_KEY_LEN as
+ 32.
+
+ [ Test Plan ]
+
+ 1. Setup: Ubuntu 24.04 LTS running 6.8 kernel (e.g. 6.8.0-134-generic /
6.8.0-138-generic).
+ 2. Keyring verification via add_key() syscall:
+ Attempt to instantiate CephX keys into the kernel keyring:
+ - 16-byte key (AES-128): accepted (return > 0, errno 0).
+ - 32-byte key (AES-256):
+ - Without patch: kernel rejects the key with return -1, errno 22
(-EINVAL) and logs "libceph: secret too big 32" to dmesg.
+ - With patch: kernel accepts the 32-byte key into the keyring (return >
0, errno 0) with zero errors in dmesg.
+ 3. Functional Ceph Test:
+ Execute "rbd map <pool>/<image>" against a Ceph 19.2.6+ cluster using an
AES-256 key.
+ - Without patch: rbd map fails with "(22) Invalid argument".
+ - With patch: block device maps cleanly to /dev/rbd0 and allows standard
filesystem mount and I/O.
+
+ [ Where problems could occur ]
+
+ The change is strictly scoped to net/ceph/crypto.h and
+ net/ceph/crypto.c.
+
+ Increasing CEPH_MAX_KEY_LEN from 16 to 32 bytes allows both legacy
+ 128-bit (16-byte) keys and modern 256-bit (32-byte) keys. Key memory is
+ allocated dynamically based on key->len or held in fixed buffers
+ dimensioned to CEPH_MAX_KEY_LEN.
+
+ Existing 16-byte keys and existing Ceph deployments are completely
+ unaffected. Regression risk is negligible.
+
+ [ Other Info ]
+
+ - Upstream status: Mainline Linux already uses CEPH_MAX_KEY_LEN 32 in
net/ceph/crypto.h.
+ - Security context: Companion kernel fix required for CVE-2025-30156 (AES-256
CephX keys).
+ - Target releases: Ubuntu 24.04 LTS (Noble linux 6.8) and Ubuntu 26.04
(Resolute linux 7.0).
+ - Patch: Attached to bug as lp-2166680-libceph-allow-256-bit-aes-keys.patch
(type: patch).
+
+ --- [ Original Report ]
------ Context
A first step to fix https://ubuntu.com/security/CVE-2025-30156 is to build
ceph-common packages with ceph 19.2.6+ and 20.2.4+. That will fix allowing the
use of aes256 keys on the user space
For Ubuntu Noble (24.04) there is a build with 19.2.6 for the proposed
channel https://launchpad.net/ubuntu/noble/+package/ceph-common
For Ubuntu Resolut (26.04) it seems to be behind
https://launchpad.net/ubuntu/resolute/+package/ceph-common
Now, this also needs to be fixed on the kernel space, else it will
complain about the length of the cephX keys used
------ Versions
$ lsb_release -a | grep Release
Release: 24.04
$ ceph --version
ceph version 20.2.4 (7f793731f1b39eb4f465e960113d2363c311b964) tentacle
(stable)
$ uname -r
6.8.0-138-generic
------ Reproduce error log
$ rbd map rbd/gus1
rbd: failed to add secret 'client.admin' to kernel
In some cases useful info is found in syslog - try "dmesg | tail".
rbd: map failed: (22) Invalid argument
$ dmesg | tail|
[345785.965860] libceph: secret too big 32
** Tags added: ceph noble rbd regression-update resolute
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166680
Title:
6.8.0 - rbd kernel module does not allow 256 cephx keys
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166680/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs