handle_auth_session_key of the component libceph. The manipulation of the argument len results in out-of-bounds write.This vulnerability is identified as CVE-2025-68284. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.