OESA-2022-1528
Dashboard / Vulnerabilities / OESA-2022-1528
Summary: ceph security update
Details: User space components of the Ceph file system. Security Fix(es): The key length for encrypted devices created using ceph-volume is incorrect. This is due to a bug in ceph_volume/util/encryption.py, where upon writing a key using osd_dmcrypt_key_size it does not pass the key size to the format and open operations following. The default key is then applied in cryptsetup. All versions since Luminous are assumed affected.(CVE-2021-3979)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1528, https://nvd.nist.gov/vuln/detail/CVE-2021-3979
Affected packages
Package
Name: ceph
Purl: pkg:rpm/openEuler/ceph&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
