REDHAT-BUG-2024788: Medium severity ceph ceph-volume vulnerability
The key length for encrypted devices created using ceph-volume is incorrect. This is due to a bug in cephvolume/util/encryption.py, where upon writing a key using osddmcryptkeysize it does not pass the key size to the format and open operations following. The default key is them applied in cryptsetup. All versions since Luminous are assumed affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2024788?
The severity of REDHAT-BUG-2024788 is considered high due to its impact on the encryption key length for Ceph storage systems.
How do I fix REDHAT-BUG-2024788?
To fix REDHAT-BUG-2024788, update your ceph-volume to a version where the key length bug has been patched.
What software is affected by REDHAT-BUG-2024788?
REDHAT-BUG-2024788 affects Ceph ceph-volume starting from the Luminous version.
What is the main issue described in REDHAT-BUG-2024788?
The main issue in REDHAT-BUG-2024788 is that the incorrect key length is used for encrypted devices created with ceph-volume.
How can I verify if my installation is vulnerable to REDHAT-BUG-2024788?
You can verify if your installation is vulnerable to REDHAT-BUG-2024788 by checking if the current installed version of ceph-volume is equal to or older than the Luminous version.