Red Hat Bugzilla – Bug 1142073
CVE-2014-6418 kernel: libceph: missing validation of auth reply
Last modified: 2018-08-28 17:55:41 EDT
A flaw was found in the kernels handling of ceph authentication tickets. The auth reply could be returned to a client unvalidated.
Statement: This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7.0 and Red Hat Enterprise MRG 2 (as they did not include support for this feature).
Upstream fixes: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c27a3e4d667fdcad3db7b104f75659478e0c68d8
The tracking bug [bug 1142287] has been closed as dupe, being tracked in BZ 1142285.