CVE-2022-3650: High severity redhat Ceph vulnerability
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.
Other sources
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump and dump privileged information.
— Microsoft
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-3650?
CVE-2022-3650 is a privilege escalation flaw found in Ceph, specifically in the Ceph-crash.service component.
How does CVE-2022-3650 impact my system?
CVE-2022-3650 allows a local attacker to escalate privileges to root by exploiting the crash dump functionality and accessing privileged information.
What is the severity of CVE-2022-3650?
The severity of CVE-2022-3650 is rated as high, with a severity value of 7.8.
How can I fix CVE-2022-3650?
To mitigate CVE-2022-3650, update your Ceph package to version 17.2.5-0ubuntu0.22.10.3 or higher, 17.2.6-0ubuntu0.23.04.2 or higher, or 17.2.6 or higher depending on your distribution.
Where can I find more information about CVE-2022-3650?
More information about CVE-2022-3650 can be found in the provided references: [link1], [link2], [link3].