cbcvebase.
CVE-2025-52555
published 2025-06-26

CVE-2025-52555: Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can…

PriorityP337medium6.5CVSS 3.1
AVAACHPRLUINSCCHILAN
EPSS
0.17%
6.6th percentile
Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by root to gain access. The result of this is that a user could read, write and execute to any directory owned by root as long as they chmod 777 it. This impacts confidentiality, integrity, and availability. It is patched in versions 17.2.8, 18.2.5, and 19.2.3.

Affected

9 ranges
VendorProductVersion rangeFixed in
cephceph
cephceph
cephceph
cephceph>= 0 < 14.2.21-1+deb11u114.2.21-1+deb11u1
cephceph>= 0 < 18.2.6-118.2.6-1
cephceph>= 0 < 18.2.6-118.2.6-1
debianceph< ceph 14.2.21-1+deb11u1 (bullseye)ceph 14.2.21-1+deb11u1 (bullseye)
msrcazl3_ceph_18.2.2-8_on_azure_linux_3.0
msrcazl3_ceph_18.2.2-9_on_azure_linux_3.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.