Database/Control plane, storage & DevOps
Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alter
Impact
The CephX signature calculation can be bypassed, so an on-path attacker can alter the payload of an authenticated Ceph message without the signature failing. In practice that means tampering with another tenant's in-flight RADOS operations - silent data corruption on a shared pool with no authentication failure logged.
Who can reach it
An on-path attacker on the Ceph public or cluster network who can modify frames in transit.
What to do
Upgrade to a fixed Ceph release and restart all daemons. Turn on msgr2 secure mode so integrity is protected by real AEAD rather than the legacy signature, and keep the cluster network physically or logically separate from tenant traffic.
References
Related entries
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostCVE-2018-12207 · Intel Core and Xeon CPUs - INTEL-SA-00210Medium
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningCVE-2018-3979 · Nouveau display driver (in-tree Linux nouveau, NV117)Medium
- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakCVE-2019-11135 · Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270Medium
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagCVE-2021-3524 · Ceph RGWMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.