cbcvebase.
CVE-2021-3979
published 2022-08-25

CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to…

PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.44%
35.2th percentile
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 16.2.9+ds-1 (bookworm)ceph 16.2.9+ds-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage>= 0 < 14.2.21-1+deb11u114.2.21-1+deb11u1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 12.2.13-0ubuntu0.18.04.1112.2.13-0ubuntu0.18.04.11
redhatceph_storage>= 0 < 15.2.17-0ubuntu0.20.04.315.2.17-0ubuntu0.20.04.3
redhatceph_storage>= 0 < 17.2.5-0ubuntu0.22.04.317.2.5-0ubuntu0.22.04.3
redhatceph_storage_for_ibm_z_systems
redhatceph_storage_for_power
redhatopenshift_container_storage
redhatopenshift_data_foundation
redhatopenstack_platform

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.