#VU17097 Memory corruption in Ceph - CVE-2018-16846
Published: January 21, 2019
Ceph
Red Hat Inc.
Description
The vulnerability allows a remote authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the RADOS Gateway (RGW) code base due to boundary error in the ListBucket max-keys function during bucket listing operations. A remote attacker with Ceph RGW user permissions can trigger memory corruption and perform a denial of service attack against object maps (OMAPs) holding bucket indexes.