Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 11 Ceph DLA-4460-1 Fix for CVE-2022-0670 Denial of Service

debian lts
Calendar Grey February 1, 2026
Dist Debian Esm H88
Discover crucial Ceph security updates for Debian LTS addressing important file system issues and DoS threats.
Ceph is a distributed object, block, and file storage platform

Summary

CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system
"share", which enables the owner to read/write any manilla share
or entire file system. The vulnerability is due to a bug in the
"volumes" plugin in Ceph Manager. This allows an attacker to
compromise confidentiality and integrity of a file system.

CVE-2024-47866

Using the argument `x-amz-copy-source` to put an object and
specifying an empty string as its content leads to the RGW daemon
crashing, resulting in a DoS attack.

For Debian 11 bullseye, these problems have been fixed in version
14.2.21-1+deb11u2.

We recommend that you upgrade your ceph packages.

For the detailed security status of ceph please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ceph

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: ceph
Version: 14.2.21-1+deb11u2
CVE ID: CVE-2022-0670 CVE-2024-47866
Debian Bug: 1016069 1120797

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here