Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70058.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-70058
Upstream
Published
2025-11-12T19:15:34Z
Modified
2026-04-01T05:21:41.121860Z
Summary
CVE-2024-47866 affecting package ceph for versions less than 18.2.2-12
Details

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument x-amz-copy-source to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.

References

Affected packages

Azure Linux:3 / ceph

Package

Name
ceph
Purl
pkg:rpm/azure-linux/ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.2.2-12

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70058.json"