News

USN-8867-1: Ceph RGW vulnerability patched for Ubuntu 18.04-26.04 LTS

Canonical has published USN-8867-1: a bug in Ceph's S3 gateway allowed unsigned x-amz- headers to be forced through. Patches are available for all LTS releases.

UptimeMag editorial team · 5 October 2026 · 1 min read

USN-8867-1: vulnerabilità in Ceph RGW, patch per Ubuntu 18.04-26.04 LTS

Canonical published the USN-8867-1 advisory on 5 October 2026, fixing a vulnerability in the Ceph package affecting the RGW object gateway. It concerns anyone running S3-compatible distributed storage on Ubuntu 26.04, 22.04, 20.04 and 18.04 LTS: a flaw in the SigV4 authentication module could allow someone holding a presigned URL to add unsigned headers and gain privileges beyond those granted by the original signer.

The problem

According to the official Ubuntu advisory, RGW's SigV4 handler failed to reject requests containing x-amz- headers that were absent from the set of signed headers. An attacker in possession of a presigned URL could therefore attach arbitrary, unsigned x-amz- headers, which RGW would still accept, allowing them to escalate privileges beyond what the signature's creator had intended. The flaw is tracked as CVE-2026-54330.

Packages and fixed versions

Ubuntu release Package Fixed version
26.04 LTS (resolute) librgw2, radosgw 20.2.0-0ubuntu2.1
22.04 LTS (jammy) librgw2, radosgw 17.2.9-0ubuntu0.22.04.4
20.04 LTS (focal) librgw2, radosgw 15.2.17-0ubuntu0.20.04.6+esm2 — requires Ubuntu Pro
18.04 LTS (bionic) librgw2, radosgw 12.2.13-0ubuntu0.18.04.11+esm3 — requires Ubuntu Pro

For 20.04 and 18.04 the fix falls under Extended Security Maintenance and requires an Ubuntu Pro subscription, which Canonical states in the same advisory is free for up to 5 machines.

What to do

A standard system update applies all the necessary changes: sudo apt update && sudo apt upgrade. After updating, check the installed version with dpkg -l librgw2 radosgw and compare it against the figures in the table above. Anyone exposing RGW as an S3 endpoint on the internet should treat this patch as a priority, given the potential for privilege escalation via presigned URLs that may already be in circulation.

Official reference: Ubuntu Security Notices, USN-8867-1, published 5 October 2026 (ubuntu.com/security/notices/USN-8867-1).

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.