Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50152

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.2

Описание

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  mon allow r capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

A flaw was found in the MON subscription handler of Ceph, a distributed storage system. The handler does not properly authorize access to the config-key store when processing MMonSubscribe messages. Any CephX user holding mon allow r capabilities can read the entire config-key store, which contains sensitive operational secrets including OSD LUKS disk encryption passphrases and, on clusters managed by cephadm, the SSH private key used to administer every host. Exposure of these secrets can lead to full host-level root access and compromise of encrypted data at rest.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it can be exploited from the adjacent cluster network with low-privilege CephX credentials and no user interaction. Successful exploitation allows an attacker to read the full MON config-key store, exposing OSD LUKS passphrases and cephadm SSH private keys, potentially yielding root access on all cluster hosts. The vulnerability's root cause is missing authorization checks in the MON subscription handler when serving config-key store contents.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 4cephFix deferred
Red Hat Ceph Storage 5cephFix deferred
Red Hat Ceph Storage 6cephFix deferred
Red Hat Ceph Storage 7cephFix deferred
Red Hat Ceph Storage 7rhceph/rhceph-7-rhel9Fix deferred
Red Hat Ceph Storage 8cephFix deferred
Red Hat Ceph Storage 8rhceph/rhceph-8-rhel9Fix deferred
Red Hat Ceph Storage 9cephFix deferred
Red Hat Ceph Storage 9rhceph/rhceph-9-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2519423ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
11 дней назад

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

CVSS3: 9.1
nvd
11 дней назад

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

CVSS3: 9.1
debian
11 дней назад

Ceph is an open-source distributed storage platform providing object, ...

8.2 High

CVSS3