Description
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3629-1 | ceph security update |
Debian DLA |
DLA-4310-1 | ceph security update |
EUVD |
EUVD-2021-27181 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. |
Ubuntu USN |
USN-6063-1 | Ceph vulnerabilities |
References
History
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-03T18:08:00.683Z
Reserved: 2021-11-19T00:00:00.000Z
Link: CVE-2021-3979
No data.
Status : Modified
Published: 2022-08-25T20:15:09.473
Modified: 2025-11-03T19:15:40.360
Link: CVE-2021-3979
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN