You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
crash service vulnerability
About this tag
The crash service vulnerability tag covers a specific local privilege escalation flaw in Ceph's crash-handling service, tracked as CVE-2022-3650. This vulnerability allows an attacker with low privileges to escalate to root by abusing the cluster crash-dump path. The tag content discusses the impact, upstream fixes, backports, and security updates from major distributions. It is relevant for system administrators and IT professionals managing Ceph storage clusters who need to understand the operational risk and apply patches. The tag focuses on this single vulnerability and does not cover other crash service issues or general privilege escalation topics.
A critical local privilege‑escalation bug in Ceph’s crash‑handling service — tracked as CVE‑2022‑3650 — lets an attacker with low privileges escalate to root by abusing the cluster crash‑dump path, and operators must treat it as a high‑impact, operational risk until patched. Multiple downstream...