CVE-2020-25660
NixOS vulnerability analysis and mitigation

Overview

A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is vulnerable to replay attacks in Nautilus. This vulnerability is tracked as CVE-2020-25660 and is notably a reintroduction of a previous vulnerability (CVE-2018-1128). The issue affects the msgr2 protocol, which is used for all communication except for older clients that do not support it (NVD, Ceph Blog).

Technical details

The vulnerability was introduced in commit 321548010578 ("mon/MonClient: skip CEPHX_V2 challenge if client doesn't support it") due to commit c58c5754dfd2 ("msg/async/ProtocolV1: use AuthServer and AuthClient"). The issue arose because commit c58c5754dfd2 wasn't backported to nautilus, and although msgr1 isn't affected in nautilus, msgr2 is the default. This caused authorizer challenges to be skipped for peers which did not support CEPHX_V2, effectively disabling the protection that was put in place in commit f80b848d3f83 (OSS Security).

Impact

The vulnerability allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via packet sniffing and perform actions allowed by the Ceph service. The highest threat from this vulnerability is to confidentiality, integrity, and system availability. The CVSS v3.1 base score is 8.8 (HIGH) with vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Exploitability

The vulnerability requires network access to the Ceph cluster and the ability to sniff packets on the network. The msgr2 protocol is affected, while the msgr1 protocol is not. The flaw specifically impacts the authentication mechanism, allowing replay attacks against the Ceph service (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Ceph versions 15.2.6 and 14.2.14. Users are recommended to upgrade to these or later versions. The fixes were implemented through multiple commits in both version branches, including patches to address the authentication verification issue (Ceph Blog, Ceph Nautilus).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18511HIGH7.8
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18846HIGH7.5
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18509HIGH7.1
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18715MEDIUM6.5
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18671MEDIUM5.3
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management