• CVE-2025-52555

发布时间: 2025年7月18日

修改时间: 2025年7月26日

概要

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by root to gain access. The result of this is that a user could read, write and execute to any directory owned by root as long as they chmod 777 it. This impacts confidentiality, integrity, and availability. It is patched in versions 17.2.8, 18.2.5, and 19.2.3.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Adjacent
CVSS评分 N/A 6.5
Attack Complexity High
Privileges Required Low
Scope Changed
Integrity Low
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2792 ceph security update 2025年9月15日

影响产品

产品 状态
V6 ceph Fixed