The vendor explicitly identifies these products as affected by this CVE.
- ceph-base as a component of Red Hat Ceph Storage 9
- ceph-common as a component of Red Hat Ceph Storage 9
- ceph-fuse as a component of Red Hat Ceph Storage 9
- ceph-immutable-object-cache as a component of Red Hat Ceph Storage 9
- ceph-mib as a component of Red Hat Ceph Storage 9
- ceph-resource-agents as a component of Red Hat Ceph Storage 9
- ceph-selinux as a component of Red Hat Ceph Storage 9
- ceph.src as a component of Red Hat Ceph Storage 9
- cephadm as a component of Red Hat Ceph Storage 9
- cephfs-top as a component of Red Hat Ceph Storage 9
- libcephfs-devel as a component of Red Hat Ceph Storage 9
- libcephfs-proxy2 as a component of Red Hat Ceph Storage 9
- Summary
- A flaw was found in Bouncy Castle for Java. The library's Cryptographic Message Syntax (CMS) component, which handles digital signature verification, incorrectly validates data that has no signers. This means that even if data is not digitally signed, the system might still consider it legitimate. This could allow an attacker to bypass critical security checks and potentially introduce unauthorized or malicious content.
- Remediation
- Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcpkix-fips 1.0.12/2.0.12/2.1.12) once available for the affected product.
