CVE-2016-5009: Red Hat Ceph

Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.

The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.

Affected products

  • Red Hat Ceph: up to and including 0.94.6
  • Red Hat Ceph Storage Mon: version 1.3 only
  • Red Hat Ceph Storage Osd: version 1.3 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2016-07-12. Last modified 2026-06-17.