A vulnerability has been found in Ceph which can lead to root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202312-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Ceph: Root Privilege Escalation Date: December 23, 2023 Bugs: #878277 ID: 202312-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in Ceph which can lead to root privilege escalation. Background ========== Ceph is a distributed network file system designed to provide excellent performance, reliability, and scalability. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ sys-cluster/ceph < 17.2.6 > = 17.2.6 Description =========== A vulnerability has been discovered in Ceph. Please review the CVE identifier referenced below for details. Impact ====== The ceph-crash.service runs the ceph-crash Python script as root. The script is operating in the directory /var/lib/ceph/crash which is controlled by the unprivileged ceph user (ceph:ceph mode 0750). The script periodically scans for new crash directories and forwards the content via `ceph crash post`. Workaround ========== There is no known workaround at this time. Resolution ========== All Ceph users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/ceph-17.2.6" References ========== [ 1 ] CVE-2022-3650 https://nvd.nist.gov/vuln/detail/CVE-2022-3650 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202312-10 Concerns? ========= Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.