Database/Control plane, storage & DevOps
Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followed
Impact
An unauthenticated client can crash radosgw by sending valid headers followed by an abrupt termination. Repeating it keeps the S3 endpoint down, which stalls every dataset loader and checkpoint writer that goes through object storage.
Who can reach it
Any host that can open a TCP connection to the RGW port. No credentials required, so a single tenant container with egress to the gateway is enough.
What to do
Upgrade RGW to a release with the Beast frontend fix and restart radosgw. Run multiple gateways behind a load balancer with aggressive health checking and per-source connection rate limits.
References
Related entries
- Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningCVE-2019-19728 · Slurm (srun --uid)High
- Lustre ptlrpc / mdt modules (client-driven server panic family): The head of a family of ten Lustre defectsCVE-2019-20423 · Lustre ptlrpc / mdt modules (client-driven server panic family)High
- Lustre (mdt module, mdt_object_remote): A client sends a packet with unvalidated fields and the metadata serverCVE-2019-20424 · Lustre (mdt module, mdt_object_remote)High
- Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.CVE-2019-20425 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, endingCVE-2019-20426 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means serverCVE-2019-20428 · Lustre (ptlrpc module)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.