The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
https://github.com/ceph/ceph/pull/9700
https://github.com/ceph/ceph/commit/957ece7e95d8f8746191fd9629622d4457d690d6
https://access.redhat.com/errata/RHSA-2016:1385
https://access.redhat.com/errata/RHSA-2016:1384
http://tracker.ceph.com/issues/16297
http://lists.opensuse.org/opensuse-updates/2016-12/msg00126.html