Resource management error in Ceph - CVE-2019-10222
Published: August 29, 2019
Vulnerability identifier: #VU20465
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10222
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to failure in the RADOS gateway implementation when handing client disconnects. A remote authenticated attacker can abuse this error and perform denial of service attack.
Affected software
Ceph
Red Hat Ceph Storage
ceph (Ubuntu package)
ceph (Alpine package)
ceph
Opensuse
Fedora
Red Hat Ceph Storage
ceph (Ubuntu package)
ceph (Alpine package)
ceph
Opensuse
Fedora
How to mitigate CVE-2019-10222
Install updates from vendor's website.
Ceph - addressed in versions 12.2.12, 13.2.6
ceph (Ubuntu package) - addressed in versions 12.2.12-0ubuntu0.18.04.1, 13.2.6-0ubuntu0.19.04.1, 13.2.6-0ubuntu0.19.04.2
ceph (Alpine package) - update to 14.2.3-r0
ceph - addressed in versions 14.2.3-1.fc30, 14.2.3-1.fc31, 14.2.3-1.fc32
ceph (Ubuntu package) - addressed in versions 12.2.12-0ubuntu0.18.04.1, 13.2.6-0ubuntu0.19.04.1, 13.2.6-0ubuntu0.19.04.2
ceph (Alpine package) - update to 14.2.3-r0
ceph - addressed in versions 14.2.3-1.fc30, 14.2.3-1.fc31, 14.2.3-1.fc32