<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 20:09:32 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-0670</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-0670</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ceph&lt;/p&gt;
&lt;p&gt;A flaw was found in Openstack manilla owning a Ceph File system &amp;#34;share&amp;#34;, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the &amp;#34;volumes&amp;#34; plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ceph&lt;/p&gt;
&lt;p&gt;A flaw was found in Openstack manilla owning a Ceph File system &amp;#34;share&amp;#34;, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the &amp;#34;volumes&amp;#34; plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-0670</guid>
    </item>
    <item>
      <title>USN-6063-1 — ceph vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-6063-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: ceph, Ubuntu:20.04:LTS: ceph, Ubuntu:22.04:LTS: ceph&lt;/p&gt;
&lt;p&gt;Mark Kirkwood discovered that Ceph incorrectly handled certain key lengths.
An attacker could possibly use this issue to create non-random encryption
keys. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-3979)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled the volumes plugin. An
attacker could possibly use this issue to obtain access to any share. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-0670)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled crash dumps. A local
attacker could possibly use this issue to escalate privileges to root. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-3650)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled URL processing on RGW
backends. An attacker could possibly use this issue to cause RGW to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS
and Ubuntu 22.10. (CVE-2022-3854)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: ceph, Ubuntu:20.04:LTS: ceph, Ubuntu:22.04:LTS: ceph&lt;/p&gt;
&lt;p&gt;Mark Kirkwood discovered that Ceph incorrectly handled certain key lengths.
An attacker could possibly use this issue to create non-random encryption
keys. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-3979)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled the volumes plugin. An
attacker could possibly use this issue to obtain access to any share. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-0670)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled crash dumps. A local
attacker could possibly use this issue to escalate privileges to root. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.
(CVE-2022-3650)&lt;/p&gt;
&lt;p&gt;It was discovered that Ceph incorrectly handled URL processing on RGW
backends. An attacker could possibly use this issue to cause RGW to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS
and Ubuntu 22.10. (CVE-2022-3854)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-6063-1</guid>
    </item>
  </channel>
</rss>
