Bug 1576057 (CVE-2018-1129) - CVE-2018-1129 ceph: cephx uses weak signatures
Summary: CVE-2018-1129 ceph: cephx uses weak signatures
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-1129
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Aron Gunn
URL:
Whiteboard:
Depends On: 1576438 1576439 1576440 1599405 1599408 1662077
Blocks: 1574281
TreeView+ depends on / blocked
 
Reported: 2018-05-08 16:56 UTC by Siddharth Sharma
Modified: 2021-12-10 16:07 UTC (History)
18 users (show)

Fixed In Version: ceph 10.2.11, ceph 12.2.6, ceph 13.2.1
Clone Of:
Environment:
Last Closed: 2019-07-24 09:06:58 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2177 0 None None None 2018-07-11 18:11:02 UTC
Red Hat Product Errata RHSA-2018:2179 0 None None None 2018-07-11 18:21:19 UTC
Red Hat Product Errata RHSA-2018:2261 0 None None None 2018-07-26 18:06:34 UTC
Red Hat Product Errata RHSA-2018:2274 0 None None None 2018-07-26 15:36:12 UTC

Description Siddharth Sharma 2018-05-08 16:56:30 UTC
A flaw was found in the way signature calculation is handled by cephx protocol. The signature calculation is encrypting a 29 byte struct with 16-byte block AES cipher, and then using the first 8 bytes of the result as signature. This only covers first (16 by tes) cipher block, data_crc falls on second block.There are no known exploits against this, If attacker can alter the message payload any changes in data_crc will not be noticed or checked by signature check.

Comment 5 Siddharth Sharma 2018-07-09 17:08:54 UTC
Created ceph tracking bugs for this issue:

Affects: fedora-all [bug 1599408]

Comment 6 errata-xmlrpc 2018-07-11 18:10:54 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 3.0 for Ubuntu 16.04

Via RHSA-2018:2177 https://access.redhat.com/errata/RHSA-2018:2177

Comment 7 errata-xmlrpc 2018-07-11 18:21:11 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 3 for Red Hat Enterprise Linux 7

Via RHSA-2018:2179 https://access.redhat.com/errata/RHSA-2018:2179

Comment 10 errata-xmlrpc 2018-07-26 15:36:03 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 2 for Ubuntu 16.04

Via RHSA-2018:2274 https://access.redhat.com/errata/RHSA-2018:2274

Comment 11 errata-xmlrpc 2018-07-26 18:06:27 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7

Via RHSA-2018:2261 https://access.redhat.com/errata/RHSA-2018:2261

Comment 13 Product Security DevOps Team 2019-07-24 09:06:58 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-1129


Note You need to log in before you can comment on or make changes to this bug.