Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2022-0138 Critical: Ceph Key Length Security Flaw Fix

mageia
Calendar Grey April 13, 2022
Dist Mageia Esm H88
Revised ceph patches address critical key length vulnerability affecting encryption on devices. Discover further insights on the correction specifics.
Updated ceph packages fix security vulnerabilities: the key length for encrypted devices created using ceph-volume is incorrect

Summary

Updated ceph packages fix security vulnerabilities: the key length for encrypted devices created using ceph-volume is incorrect. This is due to a bug in ceph_volume/util/encryption.py which is fixed by this new version. (CVE-2021-3979)

References

- https://bugs.mageia.org/show_bug.cgi?id=29871

- https://www.openwall.com/lists/oss-security/2022/01/11/5

- https://www.cve.org/CVERecord?id=CVE-2021-3979

Resolution

SRPMS

- 8/core/ceph-15.2.16-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Apr 2022
URL: https://advisories.mageia.org/MGASA-2022-0138.html
Type: security
CVE: CVE-2021-3979

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here