A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.
A flaw was found in rados gateway shipped as part of ceph. Unclosed file descriptors while denying TCP connections to SSL serving port pile up until exhaustion of resources leading to potencial remote denial of service.
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1674929]
This flaw does not affect ceph version as shipped with Red Hat Ceph Storage 2 and Red Hat Ceph Storage 3.