Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.1: 2020:2057-1 Moderate: Ceph Threat Fix

opensuse
Calendar Grey November 27, 2020
Dist Opensuse Esm H88
openSUSE reveals a security patch for ceph, tackling one significant concern along with several corrections and guidance.
An update that solves one vulnerability and has 8 fixes is now available.

Description

This update for ceph fixes the following issues:

- CVE-2020-25660: Bring back CEPHX_V2 authorizer challenges (bsc#1177843).

- Major batch refactor of ceph-volume that addresses a couple of issues

(bsc#1151612, bsc#1158257)

- Documented Prometheus' security model (bsc#1169134)

- monclient: Fixed an issue where executing several ceph commands in a

short amount of time led to a segmentation fault (bsc#1170487)

- Fixed an issue, where it was not possible to edit an iSCSI logged-in

client (bsc#1174591)

- Fixed an issue, where OSDs could not get started after they failed

(bsc#1175061)

- Fixed an issue with the restful module, where it aborted on execution

for POST calls (bsc#1175240)

- Fixed a many-to-many issue in host-details Grafana dashboard

(bsc#1175585)

- Fixed collection_list ordering in os/bluestore (bsc#1172546)

- Fixed help output of lvmcache (bsc#1175781)

This update was imported from the...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-2057=1

Package List

- openSUSE Leap 15.1 (noarch):

ceph-dashboard-e2e-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-grafana-dashboards-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-dashboard-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-diskprediction-cloud-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-diskprediction-local-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-k8sevents-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-rook-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mgr-ssh-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-prometheus-alerts-14.2.13.450+g65ea1b614d-lp151.2.28.1

- openSUSE Leap 15.1 (x86_64):

ceph-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-base-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-base-debuginfo-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-common-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-common-debuginfo-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-debugsource-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-fuse-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-fuse-debuginfo-14.2.13.450+g65ea1b614d-lp151.2.28.1

ceph-mds-14.2.13.450+...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-25660.html

https://bugzilla.suse.com/1151612

https://bugzilla.suse.com/1158257

https://bugzilla.suse.com/1169134

https://bugzilla.suse.com/1170487

https://bugzilla.suse.com/1174591

https://bugzilla.suse.com/1175061

https://bugzilla.suse.com/1175240

https://bugzilla.suse.com/1175781

https://bugzilla.suse.com/1177843

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette:

List Archives:

Announcement ID: openSUSE-SU-2020:2057-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 e.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here