Ceph monitor crash
Bug #1599545 reported by
Adam Heczko
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mirantis OpenStack |
Confirmed
|
Medium
|
MOS Ceph | ||
8.0.x |
Confirmed
|
Medium
|
MOS Ceph | ||
9.x |
Confirmed
|
Medium
|
MOS Ceph |
Bug Description
Detailed bug description:
A flaw was found in the way handle_command() function would validate prefix value from user. An authenticated attacker could send a specially crafted prefix value resulting in ceph monitor crash.
This results in denial of service (DOS).
Upstream bug report:
https:/
http://
Solution proposal:
Apply patch https:/
Steps to reproduce:
https:/
CVE References
tags: | added: feature-security |
To post a comment you must log in.
mos-ceph team, please clarify which releases are affected by this issue