Описание
A flaw was found in the CephX authentication protocol used by Ceph, a distributed storage system. CephX uses AES-128-CBC encryption with a hardcoded initialization vector and no message authentication (HMAC), making it vulnerable to the same class of unauthenticated-encryption attacks that compromised Kerberos 4 as documented in MIT's 2004 PERILS paper. An attacker who has compromised a single low-privilege CephX entity key can use the Ceph monitor as an encryption oracle by requesting tickets for specially-named entity identities over a standard network connection. The monitor encrypts these attacker-controlled names into ciphertext blocks which, due to absent integrity protection, can be spliced into forged credentials for privileged entities such as OSDs, MDSs, and MGRs. This grants cluster-wide access including data reads, data corruption, and full administrative control.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that exploitation requires a compromised low-privilege CephX entity key and network access to a Ceph monitor. Successful exploitation allows an attacker to forge credentials for any privileged Ceph entity, gaining full cluster-wide access including data reads, data corruption, and administrative control over OSDs, MDSs, and MGRs. The vulnerability's root cause is the use of unauthenticated AES-128-CBC encryption with a hardcoded initialization vector in the CephX protocol, a cryptographic design weakness identical to the one that rendered Kerberos 4 insecure.
Меры по смягчению последствий
To mitigate this issue, Red Hat recommends isolating the Ceph messenger protocol to dedicated internal networks with strict access controls, limiting exposure to potential attackers. Administrators should audit and minimize the number of CephX client credentials in circulation and enforce strong credential management to reduce the risk of low-privilege key compromise. Where possible, deploy msgr2 with on-wire encryption to reduce passive sniffing exposure. It is strongly advised to apply vendor-supplied patches as soon as they are released, upgrade to fixed Ceph versions (Tentacle 20.2.4 or later), and rotate all CephX keys to the new AES-256-CTS-HMAC-SHA384-192 cipher type, prioritizing server-side keys.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 7 | ceph | Fix deferred | ||
| Red Hat Ceph Storage 7 | cephadm | Fix deferred | ||
| Red Hat Ceph Storage 7 | rgw | Fix deferred | ||
| Red Hat Ceph Storage 8 | ceph | Fix deferred | ||
| Red Hat Ceph Storage 8 | cephadm | Fix deferred | ||
| Red Hat Ceph Storage 8 | rgw | Fix deferred | ||
| Red Hat Ceph Storage 9 | ceph | Fix deferred | ||
| Red Hat Ceph Storage 9 | cephadm | Fix deferred | ||
| Red Hat Ceph Storage 9 | rgw | Fix deferred | ||
| Red Hat Enterprise Linux 10 | kernel | Affected |
Показывать по
Дополнительная информация
Статус:
8.7 High
CVSS3
Связанные уязвимости
8.7 High
CVSS3