Resource management error in Ceph - CVE-2019-10222

 

Resource management error in Ceph - CVE-2019-10222

Published: August 29, 2019


Vulnerability identifier: #VU20465
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10222
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to failure in the RADOS gateway implementation when handing client disconnects. A remote authenticated attacker can abuse this error and perform denial of service attack.


Affected software

Ceph
Red Hat Ceph Storage
ceph (Ubuntu package)
ceph (Alpine package)
ceph
Opensuse
Fedora

How to mitigate CVE-2019-10222

Install updates from vendor's website.

Ceph - addressed in versions 12.2.12, 13.2.6
ceph (Ubuntu package) - addressed in versions 12.2.12-0ubuntu0.18.04.1, 13.2.6-0ubuntu0.19.04.1, 13.2.6-0ubuntu0.19.04.2
ceph (Alpine package) - update to 14.2.3-r0
ceph - addressed in versions 14.2.3-1.fc30, 14.2.3-1.fc31, 14.2.3-1.fc32

External References

Related Security Bulletins