VulnerabilityModified
CVE-2021-3979
An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
MEDIUM 6.5EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327, CWE-287
- Affected
- redhat/ceph storage · redhat/openshift container storage · redhat/openshift data foundation · redhat/openstack platform · redhat/ceph storage for ibm z systems · redhat/ceph storage for power · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2021-3979Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2024788Issue Tracking, Vendor Advisory
- https://github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656Patch, Third Party Advisory
- https://github.com/ceph/ceph/pull/44765Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00034.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPOK44BESMIFW6BIOGCN452AKKOIIT6Q/Mailing List
- https://tracker.ceph.com/issues/54006Issue Tracking, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2021-3979Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2024788Issue Tracking, Vendor Advisory
- https://github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656Patch, Third Party Advisory
- https://github.com/ceph/ceph/pull/44765Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00034.html
- https://lists.debian.org/debian-lts-announce/2025/09/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPOK44BESMIFW6BIOGCN452AKKOIIT6Q/Mailing List
- https://tracker.ceph.com/issues/54006Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.