Description
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.
References (4)
Core 4
Core References
Exploit, Mailing List, Third Party Advisory
https://seclists.org/oss-sec/2022/q4/41
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/OEVVWT5ZFLYCVZNDJTDX7R6RY2W7JHP5/
Third Party Advisory
https://security.gentoo.org/glsa/202312-10
Scores
CVSS v3
7.8
EPSS
0.0003
EPSS Percentile
8.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-842
Status
published
Products (1)
redhat/ceph
16.2.9
Published
Jan 17, 2023
Tracked Since
Feb 18, 2026