The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
{ "binaries": [ { "binary_name": "ceph", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-common", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-fs-common", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-fuse", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-mds", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-resource-agents", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-test", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-java", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-jni", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs1", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librados-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librados2", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librbd-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librbd1", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "python-ceph", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "radosgw", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "rbd-fuse", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "rest-bench", "binary_version": "0.80.11-0ubuntu1.14.04.3" } ], "availability": "No subscription required" }