Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 Advisory: 2023-0139 Moderate: Ceph Privilege Escalation

mageia
Calendar Grey April 15, 2023
Dist Mageia Esm H88
Latest ceph software updates for Mageia address security vulnerabilities impacting confidentiality and integrity as of April 15, 2023.
Openstack manilla owning a Ceph File system "share", enables the owner to read/write any manilla share or entire file system

Summary

Openstack manilla owning a Ceph File system "share", enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. (CVE-2022-0670) Privilege escalation and privileged information disclosure (CVE-2022-3650)

References

- https://bugs.mageia.org/show_bug.cgi?id=30677

- https://docs.ceph.com/en/latest/security/CVE-2022-0670/

-

- https://www.cve.org/CVERecord?id=CVE-2022-0670

- https://www.cve.org/CVERecord?id=CVE-2022-3650

Resolution

SRPMS

- 8/core/ceph-15.2.17-1.mga8

Publication date: 15 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0139.html
Type: security
CVE: CVE-2022-0670, CVE-2022-3650

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here