Part of a story covered by 2 sources: “Separate OpenStack Swift notices cover leak and denial of service” — merged summary and timeline →
USN-8821-1: OpenStack Swift vulnerability
AI summary · grok-4.7
Ubuntu warns an authenticated OpenStack Swift bug can cause a denial of service.
Ubuntu security notice USN-8821-1 says OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could make Swift consume excessive resources and cause a denial of service. The notice does not name a CVE or report exploitation in the wild.
- Authenticated users can exhaust Swift resources with truncated PUT bodies.
- The bug is in s3api handling of aws-chunked requests.
- The notice names no CVE and reports no active exploitation.
Full article
It was discovered that OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could possibly use this issue to cause OpenStack Swift to use excessive resources, leading to a denial of service.
This source does not provide full text. Read it at ubuntu.com.