Bug 2519431 (CVE-2026-39944) - CVE-2026-39944 ceph: ceph: RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation
Summary: CVE-2026-39944 ceph: ceph: RGW STS session tokens vulnerable to CBC bit-flip ...
Keywords:
Status: NEW
Alias: CVE-2026-39944
Deadline: 2026-08-19
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 07:59 UTC by OSIDB Bzimport
Modified: 2026-08-19 18:04 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 07:59:04 UTC
Use of a broken cryptographic algorithm vulnerability in Ceph RGW's STS session token handling. The STS tokens use the same unauthenticated AES-128-CBC handler as CephX (CVE-2025-30156) and share its lack of integrity protection. An attacker holding any valid STS token can use CBC bit-flipping to modify the token contents without detection, obtaining full RGW admin access. Unlike the CephX attack which requires access to the internal cluster network and a Ceph monitor, this attack is a self-contained modification of a token the attacker already holds, requiring only a single valid unprivileged STS token and STS to be enabled.


Note You need to log in before you can comment on or make changes to this bug.