A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the exhaustion of available resources, preventing legitimate users from connecting to the system.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ceph16Upgrade ceph | Aug 22, 2024 | Feb 7, 2020 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Feb 7, 2020 |
| Suse | — | Upgrade python3-ceph-argparseUpgrade libcephfs-develUpgrade rbd-nbdUpgrade ceph-mdsUpgrade rbd-fuseUpgrade cephfs-shellUpgrade python3-rbdUpgrade ceph-commonUpgrade ceph-testUpgrade librados-develUpgrade python3-cephfsUpgrade cephUpgrade librbd1Upgrade rados-objclass-develUpgrade ceph-fuseUpgrade rbd-mirrorUpgrade ceph-monUpgrade ceph-mgr-sshUpgrade python3-radosUpgrade ceph-mgrUpgrade ceph-resource-agentsUpgrade ceph-osdUpgrade libcephfs2Upgrade ceph-mgr-diskprediction-localUpgrade libradospp-develUpgrade ceph-mgr-rookUpgrade librgw2Upgrade librados2Upgrade libradosstriper1Upgrade librgw-develUpgrade ceph-radosgwUpgrade libradosstriper-develUpgrade ceph-dashboard-e2eUpgrade ceph-grafana-dashboardsUpgrade librbd-develUpgrade ceph-mgr-dashboardUpgrade ceph-prometheus-alertsUpgrade python3-rgwUpgrade ceph-mgr-k8seventsUpgrade ceph-mgr-diskprediction-cloudUpgrade ceph-base | Feb 9, 2020 | Feb 7, 2020 |
| Ubuntu | — | Upgrade ceph-commonUpgrade cephUpgrade ceph-base | Mar 18, 2020 | Feb 7, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub