PT-2022-6796 · Ceph+6 · Ceph+6

Matthias Gerstner

·

Published

2022-07-27

·

Updated

2025-09-25

·

CVE-2022-3650

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ceph (affected versions not specified)
Description A privilege escalation flaw was found in Ceph, specifically in the Ceph-crash.service component. This issue allows a local attacker to escalate privileges to root in the form of a crash dump, potentially gaining access to confidential data, disrupting data integrity, and causing a denial of service. The flaw is related to the improper assignment of a user to a group.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2304
AZL-38137
AZL-39295
BDU:2023-04790
CVE-2022-3650
DLA-4310-1
MGASA-2023-0139
OESA-2022-2156
OPENSUSE-SU-2024:12662-1
RHSA-2023:0980
SUSE-SU-2023:1580-1
SUSE-SU-2023:1581-1
SUSE-SU-2023:1581-2
SUSE-SU-2023:1584-1
USN-6063-1
USN-6292-1

Affected Products

Alt Linux
Astra Linux
Ceph
Debian
Linuxmint
Suse
Ubuntu