Privilege Escalation Vulnerability in Ceph Storage Platform
CVE-2025-52555

6.5MEDIUM

Key Information:

Vendor

Ceph

Status
Vendor
CVE Published:
26 June 2025

What is CVE-2025-52555?

A vulnerability in the Ceph distributed storage platform allows an unprivileged user to escalate privileges to root. By setting the permission of a directory owned by root to 777, a user can gain unauthorized read, write, and execute access to sensitive files. This issue affects CephFS in multiple versions, posing serious risks to system confidentiality, integrity, and availability. The vulnerability has been addressed in later versions, and users are advised to update their systems to prevent exploitation.

Affected Version(s)

ceph = 17.2.7 = 17.2.7

ceph >= 18.2.1, < 18.2.5 < 18.2.1, 18.2.5

ceph >= 19.0.0, < 19.2.3 < 19.0.0, 19.2.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52555 : Privilege Escalation Vulnerability in Ceph Storage Platform