Database/Control plane, storage & DevOps
Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an empty
Impact
One malformed PUT kills the radosgw process. Sending an object copy with an empty x-amz-copy-source header crashes the daemon, so a single tenant can take the shared S3 endpoint offline for everyone and stall every training job that streams checkpoints or datasets through it.
Who can reach it
Any client that can send an HTTP request to the RGW S3 endpoint. Reachable without credentials, so a tenant compute node with network access to the gateway is enough.
What to do
Upgrade RGW past 19.2.3 and restart the radosgw daemons. Run more than one RGW behind a load balancer with health checks and process supervision so a crash of one gateway does not take the endpoint down.
References
Related entries
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Sonatype Nexus Repository 3: Unauthenticated path traversalCVE-2024-4956 · Sonatype Nexus Repository 3High
- Fluent Bit: Prometheus Remote Write input crashes on a Content-Length: 0 packetCVE-2024-50608 · Fluent BitHigh
- Fluent Bit: OpenTelemetry input plugin crashes on a Content-Length: 0 packetCVE-2024-50609 · Fluent BitHigh
- Kubeflow (centraldashboard-angular backend, email validation regex): A catastrophically backtracking regex in theCVE-2024-5552 · Kubeflow (centraldashboard-angular backend, email validation regex)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.