Bug 2519423 (CVE-2026-50152) - CVE-2026-50152 ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users
Summary: CVE-2026-50152 ceph: ceph: MON subscription handler exposes config-key store ...
Keywords:
Status: NEW
Alias: CVE-2026-50152
Deadline: 2026-08-19
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 07:54 UTC by OSIDB Bzimport
Modified: 2026-08-19 18:04 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 07:54:34 UTC
Missing authorization vulnerability in the MON subscription handler of Ceph distributed storage. The flaw allows any CephX user with mon allow r capabilities to read the entire MON config-key store by sending a single crafted MMonSubscribe message. This exposes OSD LUKS passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to access every host, yielding root access under the default cephadm configuration. The attacker must have access to the Ceph cluster network and a compromised account with mon allow r permissions. No user interaction is required.


Note You need to log in before you can comment on or make changes to this bug.