Bug 2024788 (CVE-2021-3979) - CVE-2021-3979 ceph: Ceph volume does not honour osd_dmcrypt_key_size
Summary: CVE-2021-3979 ceph: Ceph volume does not honour osd_dmcrypt_key_size
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-3979
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 2018529 2027837 (view as bug list)
Depends On: 2027839 2027840 2027841 2039522
Blocks: 2018529 2025828
TreeView+ depends on / blocked
 
Reported: 2021-11-19 02:29 UTC by Sage McTaggart
Modified: 2023-07-12 08:29 UTC (History)
39 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Clone Of:
Environment:
Last Closed: 2022-05-05 13:16:09 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:1174 0 None None None 2022-04-04 10:19:49 UTC
Red Hat Product Errata RHSA-2022:1716 0 None None None 2022-05-05 07:53:16 UTC

Description Sage McTaggart 2021-11-19 02:29:50 UTC
The key length for encrypted devices created using ceph-volume is incorrect. This is due to a bug in ceph_volume/util/encryption.py, where upon writing a key using osd_dmcrypt_key_size it does not pass the key size to the format and open operations following. The default key is them applied in cryptsetup. All versions since Luminous are assumed affected.

Comment 4 Sage McTaggart 2021-11-30 20:53:14 UTC
*** Bug 2018529 has been marked as a duplicate of this bug. ***

Comment 5 Sage McTaggart 2021-12-02 20:31:13 UTC
*** Bug 2027837 has been marked as a duplicate of this bug. ***

Comment 6 Sage McTaggart 2022-01-11 21:12:51 UTC
Created ceph tracking bugs for this issue:

Affects: fedora-all [bug 2039522]

Comment 7 errata-xmlrpc 2022-04-04 10:19:45 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 5.1

Via RHSA-2022:1174 https://access.redhat.com/errata/RHSA-2022:1174

Comment 8 errata-xmlrpc 2022-05-05 07:53:13 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 4.3

Via RHSA-2022:1716 https://access.redhat.com/errata/RHSA-2022:1716

Comment 9 Product Security DevOps Team 2022-05-05 13:16:07 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-3979

Comment 10 Fedora Update System 2022-11-10 22:21:55 UTC
FEDORA-2022-d832fd2f45 has been pushed to the Fedora 37 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.