CVE-2021-3979
published 2022-08-25CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.44%
35.2th percentile
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 16.2.9+ds-1 (bookworm) | ceph 16.2.9+ds-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | >= 0 < 14.2.21-1+deb11u1 | 14.2.21-1+deb11u1 |
| redhat | ceph_storage | >= 0 < 16.2.9+ds-1 | 16.2.9+ds-1 |
| redhat | ceph_storage | >= 0 < 16.2.9+ds-1 | 16.2.9+ds-1 |
| redhat | ceph_storage | >= 0 < 16.2.9+ds-1 | 16.2.9+ds-1 |
| redhat | ceph_storage | >= 0 < 12.2.13-0ubuntu0.18.04.11 | 12.2.13-0ubuntu0.18.04.11 |
| redhat | ceph_storage | >= 0 < 15.2.17-0ubuntu0.20.04.3 | 15.2.17-0ubuntu0.20.04.3 |
| redhat | ceph_storage | >= 0 < 17.2.5-0ubuntu0.22.04.3 | 17.2.5-0ubuntu0.22.04.3 |
| redhat | ceph_storage_for_ibm_z_systems | — | — |
| redhat | ceph_storage_for_power | — | — |
| redhat | openshift_container_storage | — | — |
| redhat | openshift_data_foundation | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2023-05-09·CVSS 6.5
CVE-2021-3979 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Mark Kirkwood discovered that Ceph incorrectly handled certain key lengths.
An attacker could possibly use this issue to create non-random encryption
keys. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-3979)
It was discovered that Ceph incorrectly handled the volumes plugin. An
attacker could possibly use this issue to obtain access to any share. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-0670)
It was discovered that Ceph incorrectly handled crash dumps. A local
attacker could possibly use this issue to escalate privileges to root. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-3650)
It was
Red Hat
ceph: Ceph volume does not honour osd_dmcrypt_key_size
vendor_redhat·2022-01-11·CVSS 6.5
CVE-2021-3979 [MEDIUM] CWE-287 ceph: Ceph volume does not honour osd_dmcrypt_key_size
ceph: Ceph volume does not honour osd_dmcrypt_key_size
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Statement: Red Hat OpenStack Platform deployments use the ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.
Package: ceph (Red Hat
Debian
CVE-2021-3979: ceph - A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the...
vendor_debian·2021·CVSS 6.5
CVE-2021-3979 [MEDIUM] CVE-2021-3979: ceph - A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the...
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Scope: local
bookworm: resolved (fixed in 16.2.9+ds-1)
bullseye: resolved (fixed in 14.2.21-1+deb11u1)
forky: resolved (fixed in 16.2.9+ds-1)
sid: resolved (fixed in 16.2.9+ds-1)
trixie: resolved (fixed in 16.2.9+ds-1)
OSV
ceph vulnerabilities
osv·2023-05-09·CVSS 6.5
CVE-2021-3979 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
Mark Kirkwood discovered that Ceph incorrectly handled certain key lengths.
An attacker could possibly use this issue to create non-random encryption
keys. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-3979)
It was discovered that Ceph incorrectly handled the volumes plugin. An
attacker could possibly use this issue to obtain access to any share. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-0670)
It was discovered that Ceph incorrectly handled crash dumps. A local
attacker could possibly use this issue to escalate privileges to root. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-3650)
It was discovered that Ceph incorrectly handled URL processing on RG
GHSA
GHSA-23g5-cwwr-8xhw: A key length flaw was found in Red Hat Ceph Storage
ghsa_unreviewed·2022-08-26
CVE-2021-3979 [MEDIUM] CWE-287 GHSA-23g5-cwwr-8xhw: A key length flaw was found in Red Hat Ceph Storage
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
OSV
CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage
osv·2022-08-25·CVSS 6.5
CVE-2021-3979 [MEDIUM] CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3979https://bugzilla.redhat.com/show_bug.cgi?id=2024788https://github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656https://github.com/ceph/ceph/pull/44765https://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPOK44BESMIFW6BIOGCN452AKKOIIT6Q/https://tracker.ceph.com/issues/54006https://access.redhat.com/security/cve/CVE-2021-3979https://bugzilla.redhat.com/show_bug.cgi?id=2024788https://github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656https://github.com/ceph/ceph/pull/44765https://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2025/09/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPOK44BESMIFW6BIOGCN452AKKOIIT6Q/https://tracker.ceph.com/issues/54006
2022-08-25
Published