USN-6292-1: Ceph vulnerability
Published Aug 16, 2023
·Updated
It was discovered that Ceph incorrectly handled crash dumps. A local attacker could possibly use this issue to escalate privileges to root.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/ceph<17.2.6-0ubuntu0.23.04.2
17.2.6-0ubuntu0.23.04.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/ceph-base<17.2.6-0ubuntu0.23.04.2
17.2.6-0ubuntu0.23.04.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/ceph-common<17.2.6-0ubuntu0.23.04.2
17.2.6-0ubuntu0.23.04.2
Ubuntu Ubuntu=23.04
Event History
Aug 16, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Ceph vulnerability?
The vulnerability ID for this Ceph vulnerability is CVE-2022-3650.
2
What is the severity of CVE-2022-3650?
The severity of CVE-2022-3650 is not mentioned in the provided information.
3
What software is affected by CVE-2022-3650?
The software affected by CVE-2022-3650 is Ceph, specifically versions 17.2.6-0ubuntu0.23.04.2 and below.
4
How can a local attacker exploit CVE-2022-3650?
A local attacker could exploit CVE-2022-3650 to escalate privileges to root.
5
How can I fix CVE-2022-3650?
To fix CVE-2022-3650, update Ceph to version 17.2.6-0ubuntu0.23.04.2 or later.