First published: Wed Aug 16 2023(Updated: )
It was discovered that Ceph incorrectly handled crash dumps. A local attacker could possibly use this issue to escalate privileges to root.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ceph | <17.2.6-0ubuntu0.23.04.2 | 17.2.6-0ubuntu0.23.04.2 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/ceph-base | <17.2.6-0ubuntu0.23.04.2 | 17.2.6-0ubuntu0.23.04.2 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/ceph-common | <17.2.6-0ubuntu0.23.04.2 | 17.2.6-0ubuntu0.23.04.2 |
Ubuntu Ubuntu | =23.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Ceph vulnerability is CVE-2022-3650.
The severity of CVE-2022-3650 is not mentioned in the provided information.
The software affected by CVE-2022-3650 is Ceph, specifically versions 17.2.6-0ubuntu0.23.04.2 and below.
A local attacker could exploit CVE-2022-3650 to escalate privileges to root.
To fix CVE-2022-3650, update Ceph to version 17.2.6-0ubuntu0.23.04.2 or later.