Database/Control plane, storage & DevOps
Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosure
CVSS 7.8CVE-2022-3650Control plane, storage & DevOpscurated
Impact
ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosure
Who can reach it
Local
What to do
Data-plane: package update on every OSD/MON host
References
Related entries
- Ceph: Key length incorrectly passed to the encryption algorithmCVE-2021-3979 · CephMedium
- Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlCVE-2022-37459 · Ampere Altra before 1.08g and Altra Max before 2.05a - return address predictionHigh
- IBM Storage Scale Container Native Storage Access (pod security context): A local user in a CNSA-served containerCVE-2022-43831 · IBM Storage Scale Container Native Storage Access (pod security context)High
- IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the SpectrumCVE-2022-43867 · IBM Spectrum Scale container image (command execution)High
- AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as theCVE-2023-20555 · AMD SMM - memory corruption (AMD-SB-4003)High
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: Improper privilegeCVE-2023-20598 · AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory accessHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.