Structured the bug description with the canonical SRU template.

The regression blocks all kernel rbd mappings on Ubuntu 24.04 when Ceph
clusters enforce AES-256 CephX keys following CVE-2025-30156 fixes in
ceph-common.

The attached kernel patch bumps CEPH_MAX_KEY_LEN to 32 (matching
mainline Linux) and was verified locally on 6.8.0-134.

** Description changed:

+ [ Impact ]
+ 
+ On Ubuntu 24.04 LTS (Noble) with the 6.8 kernel series, kernel-based
+ Ceph clients (such as rbd block device mappings, ceph-fuse, and cephfs
+ kernel mounts) fail to map or mount storage when connecting to Ceph
+ clusters using updated userspace packages (ceph-common 19.2.6+ or
+ 20.2.4+):
+ 
+   $ rbd map rbd/pool1
+   rbd: failed to add secret 'client.admin' to kernel
+   In some cases useful info is found in syslog - try "dmesg | tail".
+   rbd: map failed: (22) Invalid argument
+ 
+ The kernel rejects the CephX authentication key and logs an error in
+ dmesg:
+ 
+   [345785.965860] libceph: secret too big 32
+ 
+ This regression was triggered by CVE-2025-30156 remediation. Ceph
+ userspace transitioned to 256-bit AES keys (32 bytes) for CephX
+ authentication, but the Linux 6.8 libceph module enforces a hardcoded
+ limit of CEPH_MAX_KEY_LEN = 16, resulting in a total operational failure
+ for all kernel Ceph storage mappings in Ubuntu 24.04.
+ 
+ [ Fix ]
+ 
+ In net/ceph/crypto.h, bump CEPH_MAX_KEY_LEN from 16 to 32 bytes:
+ 
+   #define CEPH_MAX_KEY_LEN 32
+ 
+ And in net/ceph/crypto.c, include the maximum allowed length in the
+ diagnostic output:
+ 
+   pr_err("secret too big %d (max %d)\n", key->len, CEPH_MAX_KEY_LEN);
+ 
+ The kernel crypto subsystem (cbc(aes)) already natively supports 256-bit
+ (32-byte) AES keys. Mainline Linux already defines CEPH_MAX_KEY_LEN as
+ 32.
+ 
+ [ Test Plan ]
+ 
+ 1. Setup: Ubuntu 24.04 LTS running 6.8 kernel (e.g. 6.8.0-134-generic / 
6.8.0-138-generic).
+ 2. Keyring verification via add_key() syscall:
+    Attempt to instantiate CephX keys into the kernel keyring:
+    - 16-byte key (AES-128): accepted (return > 0, errno 0).
+    - 32-byte key (AES-256):
+      - Without patch: kernel rejects the key with return -1, errno 22 
(-EINVAL) and logs "libceph: secret too big 32" to dmesg.
+      - With patch: kernel accepts the 32-byte key into the keyring (return > 
0, errno 0) with zero errors in dmesg.
+ 3. Functional Ceph Test:
+    Execute "rbd map <pool>/<image>" against a Ceph 19.2.6+ cluster using an 
AES-256 key.
+    - Without patch: rbd map fails with "(22) Invalid argument".
+    - With patch: block device maps cleanly to /dev/rbd0 and allows standard 
filesystem mount and I/O.
+ 
+ [ Where problems could occur ]
+ 
+ The change is strictly scoped to net/ceph/crypto.h and
+ net/ceph/crypto.c.
+ 
+ Increasing CEPH_MAX_KEY_LEN from 16 to 32 bytes allows both legacy
+ 128-bit (16-byte) keys and modern 256-bit (32-byte) keys. Key memory is
+ allocated dynamically based on key->len or held in fixed buffers
+ dimensioned to CEPH_MAX_KEY_LEN.
+ 
+ Existing 16-byte keys and existing Ceph deployments are completely
+ unaffected. Regression risk is negligible.
+ 
+ [ Other Info ]
+ 
+ - Upstream status: Mainline Linux already uses CEPH_MAX_KEY_LEN 32 in 
net/ceph/crypto.h.
+ - Security context: Companion kernel fix required for CVE-2025-30156 (AES-256 
CephX keys).
+ - Target releases: Ubuntu 24.04 LTS (Noble linux 6.8) and Ubuntu 26.04 
(Resolute linux 7.0).
+ - Patch: Attached to bug as lp-2166680-libceph-allow-256-bit-aes-keys.patch 
(type: patch).
+ 
+ --- [ Original Report ]
  ------ Context
  A first step to fix https://ubuntu.com/security/CVE-2025-30156 is to build 
ceph-common packages with ceph 19.2.6+ and 20.2.4+. That will fix allowing the 
use of aes256 keys on the user space
  
  For Ubuntu Noble (24.04) there is a build with 19.2.6 for the proposed
  channel https://launchpad.net/ubuntu/noble/+package/ceph-common
  
  For Ubuntu Resolut (26.04) it seems to be behind
  https://launchpad.net/ubuntu/resolute/+package/ceph-common
  
  Now, this also needs to be fixed on the kernel space, else it will
  complain about the length of the cephX keys used
  
  ------ Versions
  $ lsb_release -a | grep Release
  Release:      24.04
  
  $ ceph --version
  ceph version 20.2.4 (7f793731f1b39eb4f465e960113d2363c311b964) tentacle 
(stable)
  
  $ uname -r
  6.8.0-138-generic
  
  ------ Reproduce error log
  $ rbd map rbd/gus1
  rbd: failed to add secret 'client.admin' to kernel
  In some cases useful info is found in syslog - try "dmesg | tail".
  rbd: map failed: (22) Invalid argument
  
  $ dmesg | tail|
  [345785.965860] libceph: secret too big 32

** Tags added: ceph noble rbd regression-update resolute

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166680

Title:
  6.8.0 - rbd kernel module does not allow 256 cephx keys

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166680/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to