CVE-2018-16846: Medium severity redhat Ceph vulnerability
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Other sources
RGW S3 listing operations provided a way for authenticated users to cause a denial of service against OMAPs holding bucket indices.
References:
http://tracker.ceph.com/issues/35994
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16846.
What is the severity level of CVE-2018-16846?
CVE-2018-16846 has a severity level of medium.
What software versions are affected by this vulnerability?
Ceph versions before 13.2.4 are affected by this vulnerability.
How can authenticated ceph RGW users exploit this vulnerability?
Authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Where can I find more information about CVE-2018-16846?
More information about CVE-2018-16846 can be found at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.html), [2](https://access.redhat.com/errata/RHSA-2019:2538), [3](https://access.redhat.com/errata/RHSA-2019:2541).