cbcvebase.
CVE-2021-3979
published 2022-08-25

CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 16.2.9+ds-1 (bookworm)ceph 16.2.9+ds-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage>= 0 < 14.2.21-1+deb11u114.2.21-1+deb11u1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 16.2.9+ds-116.2.9+ds-1
redhatceph_storage>= 0 < 12.2.13-0ubuntu0.18.04.1112.2.13-0ubuntu0.18.04.11
redhatceph_storage>= 0 < 15.2.17-0ubuntu0.20.04.315.2.17-0ubuntu0.20.04.3
redhatceph_storage>= 0 < 17.2.5-0ubuntu0.22.04.317.2.5-0ubuntu0.22.04.3
redhatceph_storage_for_ibm_z_systems
redhatceph_storage_for_power
redhatopenshift_container_storage
redhatopenshift_data_foundation
redhatopenstack_platform

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM