A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the exhaustion of available resources, preventing legitimate users from connecting to the system.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cephUpgrade ceph16 | Aug 22, 2024 | Feb 7, 2020 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Feb 7, 2020 |
| Suse | — | Upgrade ceph-fuseUpgrade cephUpgrade ceph-testUpgrade ceph-monUpgrade ceph-mdsUpgrade rados-objclass-develUpgrade librbd1Upgrade python3-cephfsUpgrade librados-develUpgrade rbd-nbdUpgrade rbd-fuseUpgrade cephfs-shellUpgrade python3-ceph-argparseUpgrade ceph-commonUpgrade libcephfs-develUpgrade ceph-mgr-sshUpgrade rbd-mirrorUpgrade python3-rbdUpgrade python3-radosUpgrade libradosstriper1Upgrade ceph-mgr-rookUpgrade ceph-grafana-dashboardsUpgrade librbd-develUpgrade libradosstriper-develUpgrade ceph-mgr-dashboardUpgrade ceph-mgrUpgrade librgw-develUpgrade ceph-resource-agentsUpgrade ceph-dashboard-e2eUpgrade ceph-radosgwUpgrade libradospp-develUpgrade ceph-baseUpgrade ceph-prometheus-alertsUpgrade ceph-mgr-k8seventsUpgrade ceph-osdUpgrade ceph-mgr-diskprediction-cloudUpgrade ceph-mgr-diskprediction-localUpgrade libcephfs2Upgrade python3-rgwUpgrade librados2Upgrade librgw2 | Feb 9, 2020 | Feb 7, 2020 |
| Ubuntu | — | Upgrade ceph-commonUpgrade ceph-baseUpgrade ceph | Mar 18, 2020 | Feb 7, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub