A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.
The product or the administrator places a user into an incorrect group.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ceph | Redhat | 16.2.9 (including) | 16.2.9 (including) |
Ceph | Ubuntu | devel | * |
Ceph | Ubuntu | esm-infra-legacy/trusty | * |
Ceph | Ubuntu | focal | * |
Ceph | Ubuntu | jammy | * |
Ceph | Ubuntu | kinetic | * |
Ceph | Ubuntu | lunar | * |
Ceph | Ubuntu | mantic | * |
Ceph | Ubuntu | noble | * |
Ceph | Ubuntu | oracular | * |
Ceph | Ubuntu | trusty | * |
Ceph | Ubuntu | trusty/esm | * |
Ceph | Ubuntu | upstream | * |
Ceph | Ubuntu | xenial | * |
Red Hat Ceph Storage 5.3 | RedHat | ceph-2:16.2.10-138.el9cp | * |