https://seclists.org/oss-sec/2022/q4/41
Published Oct 25, 2022
·Updated
Affected Software
1 affected component
ceph ceph-base
Frequently Asked Questions
1
What is the severity of CVE-2022-40525?
The severity of CVE-2022-40525 is classified as high due to its potential for privilege escalation.
2
How do I fix CVE-2022-40525?
To fix CVE-2022-40525, upgrade to Ceph version 16.2.10 or later where the vulnerability is patched.
3
What is CVE-2022-40525 about?
CVE-2022-40525 is a vulnerability in the ceph-crash systemd service that allows local users to escalate privileges to root.
4
Which software versions are affected by CVE-2022-40525?
CVE-2022-40525 affects Ceph version 16.2.9 and earlier versions of the ceph-base component.
5
Who is impacted by CVE-2022-40525?
Users running affected versions of the Ceph distributed storage system are at risk of exploitation through CVE-2022-40525.