CVE-2021-3979

Related Vulnerabilities: CVE-2021-3979  

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Description

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Statement

Red Hat OpenStack Platform deployments use the ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.

Red Hat OpenStack Platform deployments use the ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.

Additional Information

  • Bugzilla 2024788: CVE-2021-3979 ceph: Ceph volume does not honour osd_dmcrypt_key_size
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
  • FAQ: Frequently asked questions about CVE-2021-3979