Memory corruption in Ceph - CVE-2018-16846
Published: January 21, 2019
Vulnerability details
The vulnerability allows a remote authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the RADOS Gateway (RGW) code base due to boundary error in the ListBucket max-keys function during bucket listing operations. A remote attacker with Ceph RGW user permissions can trigger memory corruption and perform a denial of service attack against object maps (OMAPs) holding bucket indexes.
Affected software
Red Hat Ceph Storage
Opensuse
Fedora
ceph
How to mitigate CVE-2018-16846
ceph - update to 12.2.11-1.fc29