USN-8045-1

Advisory lineage Upstream: 3 Downstream: 0
Published: 24 Feb 2026, 20:10
Last modified:20 May 2026, 16:03

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Feb 2026, 20:10
Published
Vulnerability first disclosed
20 May 2026, 16:03
Last Modified
Vulnerability information updated

Description

ceph vulnerabilities Martin Schobert discovered that Ceph did not properly verify SSL certificates when using Pybind for secure mail connections, which could result in accepting invalid certificates. An attacker could possibly use this issue to perform an intermediary attack and access mail server credentials or message contents. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2024-31884) It was discovered that Ceph's RADOS Gateway (RGW) did not properly handle certain header parameters. An attacker could possibly use this issue to cause the RGW service to crash, leading to a denial of service. (CVE-2024-47866)

Affected Systems

  • ubuntuceph

    < 0.80.11-0ubuntu1.14.04.4+esm4 | < 10.2.11-0ubuntu0.16.04.3+esm3 | < 12.2.13-0ubuntu0.18.04.11+esm2 | < 15.2.17-0ubuntu0.20.04.6+esm1 | < 17.2.9-0ubuntu0.22.04.2 | < 19.2.3-0ubuntu0.24.04.3 | < 19.2.3-0ubuntu1.25.10.3

References (3)