Memory leak in Ceph - CVE-2018-16889

 

Memory leak in Ceph - CVE-2018-16889

Published: January 30, 2019


Vulnerability identifier: #VU17318
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16889
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due memory leak in improper sanitization of encryption keys in debug logging output for v4 authentication. A local attacker can trigger memory leak and gain access to plaintext encryption key information in log files.


Affected software

Ceph
Red Hat Ceph Storage
Fedora
Opensuse
ceph

How to mitigate CVE-2018-16889

Install updates from vendor's website.

ceph - update to 12.2.11-1.fc29

External References

Related Security Bulletins