Medium severity6.5NVD Advisory· Published Aug 25, 2022· Updated Jun 17, 2026
CVE-2021-3979
CVE-2021-3979
Description
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30(expand)+ 6 more
- (no CPE)
- (no CPE)
- cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:5.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:*
- osv-coords16 versionspkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/opensuse/ceph&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/ceph&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ceph-test&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/fmt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/fmt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/opensuse/fmt&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/opensuse/ceph-test&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/fmt&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/ceph&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/fmt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/opensuse/ceph&distro=openSUSE%20Leap%20Micro%205.2
< 16.2.9.536+g41a9f9a5573-150400.3.3.1+ 15 more
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150400.3.3.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150400.3.3.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-1.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150400.3.3.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.3.3.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- (no CPE)range: < 8.0.1-150300.7.5.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- (no CPE)range: < 8.0.1-150300.7.5.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- (no CPE)range: < 8.0.1-150300.7.5.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- (no CPE)range: < 8.0.1-150300.7.5.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- (no CPE)range: < 8.0.1-150300.7.5.1
- (no CPE)range: < 16.2.9.536+g41a9f9a5573-150300.6.3.1
- cpe:2.3:a:redhat:openshift_container_storage:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:ceph_storage_for_ibm_z_systems:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage_for_power:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/ceph/ceph/commit/47c33179f9a15ae95cc1579a421be89378602656nvdPatchThird Party Advisory
- github.com/ceph/ceph/pull/44765nvdPatchThird Party Advisory
- access.redhat.com/security/cve/CVE-2021-3979nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- tracker.ceph.com/issues/54006nvdIssue TrackingVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPOK44BESMIFW6BIOGCN452AKKOIIT6Q/nvdMailing List
- lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlnvd
- lists.debian.org/debian-lts-announce/2025/09/msg00025.htmlnvd
News mentions
0No linked articles in our index yet.