Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

OpenSUSE Leap 42.3 Advisory 2018:2283-1 Important Ceph Security Update

opensuse
Calendar Grey August 10, 2018
Dist Opensuse Esm H88
This patch resolves significant problems in ceph, improving safety and reliability for openSUSE individuals.
An update that solves three vulnerabilities and has one errata is now available.

Description

This update for ceph fixes the following issues:

Security issues fixed:

- CVE-2018-10861: Ensure that ceph-mon does perform authorization on all

OSD pool ops (bsc#1099162)

- CVE-2018-1129: cephx signature check bypass (bsc#1096748)

- CVE-2018-1128: cephx protocol was vulnerable to replay attack

(bsc#1096748)

Bugs fixed in 12.2.7-420-gc0ef85b854:

- luminous: osd: eternal stuck PG in 'unfound_recovery' (bsc#1094932)

- bluestore: db.slow used when db is not full (bsc#1092874)

- Upstream fixes and improvements, see

https://ceph.com/en/news/blog/2018/12-2-7-luminous-released/

This update was imported from the SUSE:SLE-12-SP3:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-854=1

Package List

- openSUSE Leap 42.3 (x86_64):

ceph-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-base-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-base-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-common-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-common-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-debugsource-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-fuse-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-fuse-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mds-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mds-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mgr-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mgr-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mon-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-mon-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-osd-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-osd-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-radosgw-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-radosgw-debuginfo-12.2.7+git.1531910353.c0ef85b854-12.1

ceph-resource-agents-12.2.7+git.15319103...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-10861.html

https://www.suse.com/security/cve/CVE-2018-1128.html

https://www.suse.com/security/cve/CVE-2018-1129.html

https://bugzilla.suse.com/1092874

https://bugzilla.suse.com/1094932

https://bugzilla.suse.com/1096748

https://bugzilla.suse.com/1099162

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:2283-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here