https://seclists.org/oss-sec/2025/q2/283: CVE-2025-52555 Ceph: CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS
Published Jun 27, 2025
·Updated
Affected Software
1 affected component
ceph CephFS<17.2.8, <18.2.5, <19.2.3
Frequently Asked Questions
1
What is the severity of CVE-2025-52555?
CVE-2025-52555 is rated as a high severity vulnerability.
2
How do I fix CVE-2025-52555?
To fix CVE-2025-52555, upgrade to Ceph version 17.2.8 or later.
3
Who is affected by CVE-2025-52555?
CVE-2025-52555 affects all unprivileged users accessing CephFS through ceph-fuse.
4
What is the impact of CVE-2025-52555?
CVE-2025-52555 allows unprivileged users to escalate to root privileges on a CephFS mounted file system.
5
Is there a workaround for CVE-2025-52555?
The recommended mitigation is to avoid using chmod 777 on directories owned by root until the vulnerability is patched.