Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by root to gain access. The result of this is that a user could read, write and execute to any directory owned by root as long as they chmod 777 it. This impacts confidentiality, integrity, and availability. It is patched in versions 17.2.8, 18.2.5, and 19.2.3.
History

Fri, 27 Jun 2025 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
References
Metrics threat_severity

None

threat_severity

Important


Thu, 26 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
Description Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by root to gain access. The result of this is that a user could read, write and execute to any directory owned by root as long as they chmod 777 it. This impacts confidentiality, integrity, and availability. It is patched in versions 17.2.8, 18.2.5, and 19.2.3.
Title CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-26T20:21:05.594Z

Updated: 2025-06-26T20:40:18.751Z

Reserved: 2025-06-18T03:55:52.034Z

Link: CVE-2025-52555

cve-icon Vulnrichment

Updated: 2025-06-26T20:40:08.534Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T21:15:28.310

Modified: 2025-06-30T18:38:48.477

Link: CVE-2025-52555

cve-icon Redhat

Severity : Important

Publid Date: 2025-06-26T00:00:00Z

Links: CVE-2025-52555 - Bugzilla