Severity
6.5MEDIUM
EPSS
0.3%
top 49.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 9

Description

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages7 packages

NVDredhat/ceph_storage5 versions+4
Debianceph< 14.2.21-1+deb11u1+3
Ubuntuceph< 12.2.13-0ubuntu0.18.04.11+2
CVEListV5cephNot-Known

Also affects: Fedora 35, 37

Patches

🔴Vulnerability Details

4
OSV
ceph vulnerabilities2023-05-09
GHSA
GHSA-23g5-cwwr-8xhw: A key length flaw was found in Red Hat Ceph Storage2022-08-26
OSV
CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage2022-08-25
CVEList
CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage2022-08-25

📋Vendor Advisories

3
Ubuntu
Ceph vulnerabilities2023-05-09
Red Hat
ceph: Ceph volume does not honour osd_dmcrypt_key_size2022-01-11
Debian
CVE-2021-3979: ceph - A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the...2021
CVE-2021-3979 (MEDIUM CVSS 6.5) | A key length flaw was found in Red | cvebase.io