ceph vulnerability

Related Vulnerabilities: CVE-2019-10222  

Ceph could be made to crash if it received specially crafted network traffic.

Abhishek Lekshmanan discovered that the RADOS gateway implementation in Ceph did not handle client disconnects properly in some situations. A remote attacker could use this to cause a denial of service.

29 August 2019

ceph vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 19.04
  • Ubuntu 18.04 LTS

Summary

Ceph could be made to crash if it received specially crafted network traffic.

Software Description

  • ceph - distributed storage and file system

Details

Abhishek Lekshmanan discovered that the RADOS gateway implementation in Ceph did not handle client disconnects properly in some situations. A remote attacker could use this to cause a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
ceph - 13.2.6-0ubuntu0.19.04.3
radosgw - 13.2.6-0ubuntu0.19.04.3
Ubuntu 18.04 LTS
ceph - 12.2.12-0ubuntu0.18.04.2
radosgw - 12.2.12-0ubuntu0.18.04.2

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References