Martin Schobert discovered that Ceph did not properly verify SSL certificates when using Pybind for secure mail connections, which could result in accepting invalid certificates. An attacker could possibly use this issue to perform an intermediary attack and access mail server credentials or message contents. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2024-31884)
It was discovered that Ceph's RADOS Gateway (RGW) did not properly handle certain header parameters. An attacker could possibly use this issue to cause the RGW service to crash, leading to a denial of service. (CVE-2024-47866)
17.2.9-0ubuntu0.22.04.219.2.3-0ubuntu0.24.04.319.2.3-0ubuntu1.25.10.30.80.11-0ubuntu1.14.04.4+esm410.2.11-0ubuntu0.16.04.3+esm312.2.13-0ubuntu0.18.04.11+esm215.2.17-0ubuntu0.20.04.6+esm1