REDHAT-BUG-1546610: High severity ceph vulnerability
In ceph, HTTP request headers without a ":" character that are handled in rgwcivetweb.cc:RGW::initenv() can cause variables to be set to NULL, leading to a crash or other potentially unspecified behaviour.
Upstream Pull Request:
https://github.com/ceph/ceph/pull/20403
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1546610?
The severity of REDHAT-BUG-1546610 is considered critical due to the potential for application crashes and unspecified behavior.
How do I fix REDHAT-BUG-1546610?
To fix REDHAT-BUG-1546610, update to the latest version of Ceph where the issue has been addressed.
What versions of Ceph are affected by REDHAT-BUG-1546610?
REDHAT-BUG-1546610 affects multiple versions of Ceph, and the specific affected versions should be checked in the release notes.
What are the potential impacts of REDHAT-BUG-1546610?
The potential impacts of REDHAT-BUG-1546610 include application crashes and instability, leading to a lack of service availability.
Is there a workaround for REDHAT-BUG-1546610?
Currently, there are no known workarounds for REDHAT-BUG-1546610 aside from applying the recommended updates.