openEuler 24.03 LTS SP1 update for ceph



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-52555
CWE-ID CWE-264
Exploitation vector Local
Public exploit N/A
Vulnerable software
openEuler
Operating systems & Components / Operating system

cephfs-top
Operating systems & Components / Operating system package or component

cephadm
Operating systems & Components / Operating system package or component

ceph-volume
Operating systems & Components / Operating system package or component

ceph-resource-agents
Operating systems & Components / Operating system package or component

ceph-prometheus-alerts
Operating systems & Components / Operating system package or component

ceph-mib
Operating systems & Components / Operating system package or component

ceph-mgr-rook
Operating systems & Components / Operating system package or component

ceph-mgr-modules-core
Operating systems & Components / Operating system package or component

ceph-mgr-k8sevents
Operating systems & Components / Operating system package or component

ceph-mgr-diskprediction-local
Operating systems & Components / Operating system package or component

ceph-mgr-dashboard
Operating systems & Components / Operating system package or component

ceph-mgr-cephadm
Operating systems & Components / Operating system package or component

ceph-grafana-dashboards
Operating systems & Components / Operating system package or component

rbd-nbd
Operating systems & Components / Operating system package or component

rbd-mirror
Operating systems & Components / Operating system package or component

rbd-fuse
Operating systems & Components / Operating system package or component

rados-objclass-devel
Operating systems & Components / Operating system package or component

python3-rgw
Operating systems & Components / Operating system package or component

python3-rbd
Operating systems & Components / Operating system package or component

python3-rados
Operating systems & Components / Operating system package or component

python3-cephfs
Operating systems & Components / Operating system package or component

python3-ceph-common
Operating systems & Components / Operating system package or component

python3-ceph-argparse
Operating systems & Components / Operating system package or component

librgw2
Operating systems & Components / Operating system package or component

librgw-devel
Operating systems & Components / Operating system package or component

librbd1
Operating systems & Components / Operating system package or component

librbd-devel
Operating systems & Components / Operating system package or component

libradosstriper1
Operating systems & Components / Operating system package or component

libradosstriper-devel
Operating systems & Components / Operating system package or component

libradospp-devel
Operating systems & Components / Operating system package or component

librados2
Operating systems & Components / Operating system package or component

librados-devel
Operating systems & Components / Operating system package or component

libcephsqlite-devel
Operating systems & Components / Operating system package or component

libcephsqlite
Operating systems & Components / Operating system package or component

libcephfs2
Operating systems & Components / Operating system package or component

libcephfs-devel
Operating systems & Components / Operating system package or component

cephfs-mirror
Operating systems & Components / Operating system package or component

ceph-test
Operating systems & Components / Operating system package or component

ceph-selinux
Operating systems & Components / Operating system package or component

ceph-radosgw
Operating systems & Components / Operating system package or component

ceph-osd
Operating systems & Components / Operating system package or component

ceph-mon
Operating systems & Components / Operating system package or component

ceph-mgr
Operating systems & Components / Operating system package or component

ceph-mds
Operating systems & Components / Operating system package or component

ceph-immutable-object-cache
Operating systems & Components / Operating system package or component

ceph-fuse
Operating systems & Components / Operating system package or component

ceph-exporter
Operating systems & Components / Operating system package or component

ceph-debugsource
Operating systems & Components / Operating system package or component

ceph-debuginfo
Operating systems & Components / Operating system package or component

ceph-common
Operating systems & Components / Operating system package or component

ceph-base
Operating systems & Components / Operating system package or component

ceph
Operating systems & Components / Operating system package or component

Vendor openEuler

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU112131

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-52555

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a local unprivileged user can executed the "chmod 777" command on a ceph-fuse mounted CephFS and escalate their privileges to root. 

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS SP1

cephfs-top: before 18.2.2-8

cephadm: before 18.2.2-8

ceph-volume: before 18.2.2-8

ceph-resource-agents: before 18.2.2-8

ceph-prometheus-alerts: before 18.2.2-8

ceph-mib: before 18.2.2-8

ceph-mgr-rook: before 18.2.2-8

ceph-mgr-modules-core: before 18.2.2-8

ceph-mgr-k8sevents: before 18.2.2-8

ceph-mgr-diskprediction-local: before 18.2.2-8

ceph-mgr-dashboard: before 18.2.2-8

ceph-mgr-cephadm: before 18.2.2-8

ceph-grafana-dashboards: before 18.2.2-8

rbd-nbd: before 18.2.2-8

rbd-mirror: before 18.2.2-8

rbd-fuse: before 18.2.2-8

rados-objclass-devel: before 18.2.2-8

python3-rgw: before 18.2.2-8

python3-rbd: before 18.2.2-8

python3-rados: before 18.2.2-8

python3-cephfs: before 18.2.2-8

python3-ceph-common: before 18.2.2-8

python3-ceph-argparse: before 18.2.2-8

librgw2: before 18.2.2-8

librgw-devel: before 18.2.2-8

librbd1: before 18.2.2-8

librbd-devel: before 18.2.2-8

libradosstriper1: before 18.2.2-8

libradosstriper-devel: before 18.2.2-8

libradospp-devel: before 18.2.2-8

librados2: before 18.2.2-8

librados-devel: before 18.2.2-8

libcephsqlite-devel: before 18.2.2-8

libcephsqlite: before 18.2.2-8

libcephfs2: before 18.2.2-8

libcephfs-devel: before 18.2.2-8

cephfs-mirror: before 18.2.2-8

ceph-test: before 18.2.2-8

ceph-selinux: before 18.2.2-8

ceph-radosgw: before 18.2.2-8

ceph-osd: before 18.2.2-8

ceph-mon: before 18.2.2-8

ceph-mgr: before 18.2.2-8

ceph-mds: before 18.2.2-8

ceph-immutable-object-cache: before 18.2.2-8

ceph-fuse: before 18.2.2-8

ceph-exporter: before 18.2.2-8

ceph-debugsource: before 18.2.2-8

ceph-debuginfo: before 18.2.2-8

ceph-common: before 18.2.2-8

ceph-base: before 18.2.2-8

ceph: before 18.2.2-8

CPE2.3 External links

https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1838


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###