Database/Control plane, storage & DevOps
CephFS (via OpenStack Manila native driver): A Manila user can request access for an existing CephFS identity and get
Impact
A Manila user can request access for an existing CephFS identity and get that identity's credentials handed back, which means stealing another tenant's CephFS key. With that key the attacker mounts and reads/writes shares that belong to somebody else.
Who can reach it
Any tenant able to issue Manila share-access requests against a cluster using the native CephFS driver.
What to do
Apply the Ceph and Manila updates that scope credential creation to the requesting project, restart the manila-share and ceph-mgr volumes module, then rotate every CephFS auth ID that Manila created before the fix.
References
Related entries
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiCVE-2021-27364 · Linux iSCSIHigh
- linuxptp / ptp4l (transparent clock on little-endian): A crafted PTP packet against ptp4l running as a transparentCVE-2021-3571 · linuxptp / ptp4l (transparent clock on little-endian)High
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of dataCVE-2022-32521 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserializationHigh
- IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections fromCVE-2022-41737 · IBM Storage Scale Container Native Storage Access (namespace boundary)High
- SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outCVE-2025-6202 · SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12)High
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreCVE-2025-68313 · AMD Zen 5 RDSEED (16-bit and 32-bit variants)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.