CVE-2018-1128: Debian Linux
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Opensuse Leap: version 15.0 only
- Red Hat Ceph: from 10.2.0, up to and including 13.2.1
- Red Hat Ceph Storage: version 3 only
- Red Hat Ceph Storage Mon: version 2 only; version 3 only
- Red Hat Ceph Storage Osd: version 2 only; version 3 only
- Red Hat Enterprise Linux: version 7.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-07-10. Last modified 2026-06-17.