https://seclists.org/oss-sec/2025/q2/282: CVE-2025-52555 Ceph: CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS
Published Jun 26, 2025
·Updated
Affected Software
1 affected component
ceph CephFS<17.2.8, <18.2.5, <19.2.3
Frequently Asked Questions
1
What is the severity of CVE-2025-52555?
CVE-2025-52555 has been classified as a high severity vulnerability due to the potential for unprivileged users to escalate privileges to root.
2
How do I fix CVE-2025-52555?
To mitigate CVE-2025-52555, limit the permissions on directories and avoid allowing unprivileged users to modify directory permissions.
3
What systems are affected by CVE-2025-52555?
CVE-2025-52555 affects CephFS when it is mounted using ceph-fuse, particularly in environments with overly permissive directory settings.
4
Who can exploit CVE-2025-52555?
Any unprivileged user with access to a CephFS mounted using ceph-fuse can exploit CVE-2025-52555 if they have the ability to change directory permissions.
5
What are the potential consequences of CVE-2025-52555?
Exploitation of CVE-2025-52555 could lead to unauthorized access and manipulation of files and directories owned by root, jeopardizing system security.