It’s a CVE Kind of Day

Gemini_Generated_Image_qbfdxgqbfdxgqbfd.jpeg

by Sage McTaggart, Michael Hackett, and Federico Lucifredi

Messenger and MON #

The IBM Ceph Security team is leading the response to a high-severity security vulnerability reported by an independent researcher, coordinating closely with the Ceph Community’s upstream security response process through Sage McTaggart, who is double-hatting both roles. The vulnerability’s impact is mitigated in most deployments because it requires access to an internal cluster network typically isolated from end-users. However, where such network access exists, an attacker could bypass access controls and forge privileged credentials (CVE-2025-30156AES-CBC misuse in CephX facilitating authentication bypass).

Erin Shepherd (E43.eu) was the original reporter, with independent reports from David Mohren (CLYSO) and David Korczynski (Ada Logics / Anthropic’s Project Glasswing).

We are taking this exploit very seriously, as should our user base. We are encouraging users to upgrade their clusters at the earliest possible time regardless of their actual exposure.
Patches have already been released for the latest versions of a number of products, with backports for more to follow after public disclosure. Mechanisms for seamless upgrade have been provided in Cephadm and Rook deployments. Refer to your specific Ceph vendor for the details of the upgrade process applicable to you.

A full technical retrospective by the authors of the patch will be published later this week by the IBM Ceph team.

A separate attack vector with matching network access requirements, attacker persona, and privilege escalation outcomes has been reported by David Mohren of CLYSO (CVE-2026-50152MON config-key store improper authorization). This attack vector targets the MON daemon and exfiltrates its config-key store, exposing privileged cluster credentials. For users’ convenience, a fix for this vulnerability is shipped concurrently.

A technical analysis of this and related CVEs will be shared by the CLYSO team later this month.

Canonical plans to update the Ubuntu archives with the new releases in the coming days.

As of today’s disclosure, patches remediating both CVEs are already in place for the following product versions, listed here chronologically by release:

Red Hat Enterprise Linux 10.2, 9.8, 9.6, 9.4
IBM Storage Ceph 9.9.1.z1
Red Hat Ceph Storage 9.1.z1
Red Hat OpenStack Services on OpenShift 18
OpenShift Data Foundation 4.22, 4.21
CLYSO Enterprise Storage v20.2.4
CLYSO Enterprise Storage v19.2.6

With today’s public disclosure, we are patching Tentacle with version 20.2.4 and releasing all relevant documentation both upstream and downstream.

Additional backports will be released for the following during the coming quarter, in no particular order:
IBM Storage Ceph 8.1, 7.1, 6.1, 5.3
Red Hat Ceph Storage 8.1, 7.1, 6.1, 5.3, 4.3
Red Hat OpenStack Platform 17.1, 16.2
OpenShift Data Foundation 4.20–4.18 (Ceph 8.1), 4.17–4.14 (Ceph 7.1)
CLYSO Enterprise Storage v18.2.8-1

The Squid release will also receive a backport shortly (version 19.2.6).

Gemini_Generated_Image_7c9cv77c9cv77c9c.jpeg

RGW #

Additionally, the upstream releases for Tentacle and Squid carry remediation for an exploit against RGW (CVE-2026-54330SigV4 verifier error allows attachment of aribtrary x-amz-* headers resulting in privilege escalation), also reported by David Mohren of CLYSO and exposing improper signature validation. An attacker who holds nothing but a presigned PUT URL could inject headers the signer never authorized, resulting in privilege escalation within the RGW (not Ceph) scope.

Lastly, RGW’s STS session tokens are exposing the same cryptographic weakness as the Messenger flaw previously discussed. The same remediation applies to both, but until that is applied an adversary could escalate STS capabilities to an admin role in RGW (CVE-2026-39944Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation to RGW admin).

Age of Thinking Machines #

This release caps a major effort, involving a lot of folks across IBM, Red Hat, Clyso, Nokia, Canonical, and the broader Ceph Community to deliver fixes and disclose with resolution in place across as many products as possible. As we initiate the backport campaign, secrecy is no longer an option. We are bringing our effort to bear to make patches available as far back as Nautilus in Red Hat products, and we all stand ready to assist. It was inspiring to work with such a broad team, and I hope we get to do it again… hopefully for different reasons. Thanks to everyone who contributed.

Many (but not all) of these vulnerabilities were found with expert use of Anthropic’s Claude models in the hands of skilled analysts. The CephX remediation requires a special release effort due to the complexity of the fix, but we expect the rise of evermore advanced machine intelligence to keep us on our toes. We plan to turn around most such discoveries in the regular upgrade process going forward, as we adapt to this new normal.

Gemini_Generated_Image_qahejqqahejqqahe.jpeg

Disclosures #

CVE-2025-30156AES-CBC misuse in CephX facilitating authentication bypass

CVE-2026-50152MON config-key store improper authorization

CVE-2026-54330SigV4 verifier error allows attachment of aribtrary x-amz-* headers resulting in privilege escalation

CVE-2026-39944Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation to RGW admin

Cross-posted to the IBM Ceph Blog.

 
116
Kudos
 
116
Kudos

Now read this

Bloomberg hosts Ceph Days in NYC

The Storage Engineering team at Bloomberg graciously hosted our first Ceph Days event of the year in their New York City offices. The event was an absolute blast, it was great to see so many Community members and even colleagues face to... Continue →