CVE-2022-3650
Aliases:DEBIAN-CVE-2022-3650RHSA-2023:0980
Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 17 Jan 2023, 00:00
Last modified:03 Nov 2025, 18:08
Vulnerability Summary
Overall Risk (default)
medium
41/100 CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.33% LOW
0% probability +0.30%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
17 Jan 2023, 00:00
Published
Vulnerability first disclosed
03 Nov 2025, 18:08
Last Modified
Vulnerability information updated
Description
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.33%• Percentile: 26%
Techniques & Countermeasures
- CWE-842•Placement of User into Incorrect Group
The product or the administrator places a user into an incorrect group.
Affected Systems
- debian•ceph
< 14.2.21-1+deb11u1 | < 16.2.10+ds-4 | < 16.2.10+ds-4 | < 16.2.10+ds-4
- redhat•ceph
16.2.9
- redhat•ceph-mgr
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-cephadm
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-dashboard
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-debuginfo
< 2:16.2.10-138.el8cp | < 2:16.2.10-138.el9cp
- redhat•ceph-mgr-diskprediction-local
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-k8sevents
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-modules-core
< 2:16.2.10-138.el8cp
- redhat•ceph-mgr-rook
< 2:16.2.10-138.el8cp
References (68)
- https://seclists.org/oss-sec/2022/q4/41
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OEVVWT5ZFLYCVZNDJTDX7R6RY2W7JHP5/
- https://security.gentoo.org/glsa/202312-10
- https://lists.debian.org/debian-lts-announce/2025/09/msg00025.html
- https://security-tracker.debian.org/tracker/CVE-2022-3650
- https://access.redhat.com/errata/RHSA-2023:0980
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5.3z1/html/release_notes/index
- https://bugzilla.redhat.com/show_bug.cgi?id=2008524
- https://bugzilla.redhat.com/show_bug.cgi?id=2040337
- https://bugzilla.redhat.com/show_bug.cgi?id=2064429
- https://bugzilla.redhat.com/show_bug.cgi?id=2064441
- https://bugzilla.redhat.com/show_bug.cgi?id=2073273
- https://bugzilla.redhat.com/show_bug.cgi?id=2083468
- https://bugzilla.redhat.com/show_bug.cgi?id=2094822
- https://bugzilla.redhat.com/show_bug.cgi?id=2097680
- https://bugzilla.redhat.com/show_bug.cgi?id=2099470
- https://bugzilla.redhat.com/show_bug.cgi?id=2103677
- https://bugzilla.redhat.com/show_bug.cgi?id=2106849
- https://bugzilla.redhat.com/show_bug.cgi?id=2107407
- https://bugzilla.redhat.com/show_bug.cgi?id=2111573
- https://bugzilla.redhat.com/show_bug.cgi?id=2118263
- https://bugzilla.redhat.com/show_bug.cgi?id=2118541
- https://bugzilla.redhat.com/show_bug.cgi?id=2119100
- https://bugzilla.redhat.com/show_bug.cgi?id=2120491
- https://bugzilla.redhat.com/show_bug.cgi?id=2120497
- https://bugzilla.redhat.com/show_bug.cgi?id=2120498
- https://bugzilla.redhat.com/show_bug.cgi?id=2122275
- https://bugzilla.redhat.com/show_bug.cgi?id=2122284
- https://bugzilla.redhat.com/show_bug.cgi?id=2124417
- https://bugzilla.redhat.com/show_bug.cgi?id=2125575
- https://bugzilla.redhat.com/show_bug.cgi?id=2125578
- https://bugzilla.redhat.com/show_bug.cgi?id=2126163
- https://bugzilla.redhat.com/show_bug.cgi?id=2127110
- https://bugzilla.redhat.com/show_bug.cgi?id=2127442
- https://bugzilla.redhat.com/show_bug.cgi?id=2128215
- https://bugzilla.redhat.com/show_bug.cgi?id=2129996
- https://bugzilla.redhat.com/show_bug.cgi?id=2130667
- https://bugzilla.redhat.com/show_bug.cgi?id=2130845
- https://bugzilla.redhat.com/show_bug.cgi?id=2130901
- https://bugzilla.redhat.com/show_bug.cgi?id=2135723
- https://bugzilla.redhat.com/show_bug.cgi?id=2136407
- https://bugzilla.redhat.com/show_bug.cgi?id=2136909
- https://bugzilla.redhat.com/show_bug.cgi?id=2141164
- https://bugzilla.redhat.com/show_bug.cgi?id=2142624
- https://bugzilla.redhat.com/show_bug.cgi?id=2152053
- https://bugzilla.redhat.com/show_bug.cgi?id=2153774
- https://bugzilla.redhat.com/show_bug.cgi?id=2157952
- https://bugzilla.redhat.com/show_bug.cgi?id=2158286
- https://bugzilla.redhat.com/show_bug.cgi?id=2158690
- https://bugzilla.redhat.com/show_bug.cgi?id=2159301
- https://bugzilla.redhat.com/show_bug.cgi?id=2160209
- https://bugzilla.redhat.com/show_bug.cgi?id=2160398
- https://bugzilla.redhat.com/show_bug.cgi?id=2161478
- https://bugzilla.redhat.com/show_bug.cgi?id=2161481
- https://bugzilla.redhat.com/show_bug.cgi?id=2162135
- https://bugzilla.redhat.com/show_bug.cgi?id=2164338
- https://bugzilla.redhat.com/show_bug.cgi?id=2164853
- https://bugzilla.redhat.com/show_bug.cgi?id=2165890
- https://bugzilla.redhat.com/show_bug.cgi?id=2166652
- https://bugzilla.redhat.com/show_bug.cgi?id=2166713
- https://bugzilla.redhat.com/show_bug.cgi?id=2167549
- https://bugzilla.redhat.com/show_bug.cgi?id=2168019
- https://bugzilla.redhat.com/show_bug.cgi?id=2170812
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0980.json
- https://access.redhat.com/security/cve/CVE-2022-3650
- https://www.cve.org/CVERecord?id=CVE-2022-3650
- https://nvd.nist.gov/vuln/detail/CVE-2022-3650