A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the exhaustion of available resources, preventing legitimate users from connecting to the system.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cephUpgrade ceph16 | Aug 22, 2024 | Feb 7, 2020 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Feb 7, 2020 |
| Suse | — | Upgrade ceph-resource-agentsUpgrade ceph-dashboard-e2eUpgrade ceph-mgr-rookUpgrade ceph-mgr-diskprediction-cloudUpgrade libradospp-develUpgrade librbd-develUpgrade ceph-grafana-dashboardsUpgrade ceph-mgr-dashboardUpgrade ceph-baseUpgrade libcephfs2Upgrade ceph-mgr-diskprediction-localUpgrade ceph-radosgwUpgrade ceph-prometheus-alertsUpgrade libradosstriper1Upgrade librgw2Upgrade librgw-develUpgrade ceph-mgr-k8seventsUpgrade libradosstriper-develUpgrade librados2Upgrade ceph-mgrUpgrade python3-rgwUpgrade ceph-osdUpgrade cephUpgrade ceph-testUpgrade python3-cephfsUpgrade rbd-fuseUpgrade python3-ceph-argparseUpgrade cephfs-shellUpgrade ceph-monUpgrade librados-develUpgrade rbd-nbdUpgrade ceph-mgr-sshUpgrade rados-objclass-develUpgrade librbd1Upgrade python3-radosUpgrade ceph-mdsUpgrade python3-rbdUpgrade ceph-fuseUpgrade ceph-commonUpgrade rbd-mirrorUpgrade libcephfs-devel | Feb 9, 2020 | Feb 7, 2020 |
| Ubuntu | — | Upgrade ceph-baseUpgrade ceph-commonUpgrade ceph | Mar 18, 2020 | Feb 7, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub