Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

OpenSUSE 15.2: 2020:2327-1 Important: Ceph Privilege Escalation

opensuse
Calendar Grey December 25, 2020
Dist Opensuse Esm H88
Urgent openSUSE patch for Ceph resolves a privilege escalation vulnerability with a significant security enhancement now accessible.
An update that solves one vulnerability and has four fixes is now available

Description

This update for ceph fixes the following issues:

Security issue fixed:

- CVE-2020-27781: Fixed a privilege escalation via the ceph_volume_client

Python interface (bsc#1180155, bsc#1179802).

Non-security issues fixed:

- Update to 15.2.8-80-g1f4b6229ca:

+ Rebase on tip of upstream "octopus" branch, SHA1

bdf3eebcd22d7d0b3dd4d5501bee5bac354d5b55

* upstream Octopus v15.2.8 release, see

https://ceph.io/en/news/blog/2020/v15-2-8-octopus-released/

- Update to 15.2.7-776-g343cd10fe5:

+ Rebase on tip of upstream "octopus" branch, SHA1

1b8a634fdcd94dfb3ba650793fb1b6d09af65e05

* (bsc#1178860) mgr/dashboard: Disable TLS 1.0 and 1.1

+ (bsc#1179016) rpm: require smartmontools on SUSE

+ (bsc#1180107) ceph-volume: pass --filter-for-batch from drive-group

subcommand

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-2327=1

Package List

- openSUSE Leap 15.2 (x86_64):

ceph-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-base-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-base-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-common-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-common-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-debugsource-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-fuse-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-fuse-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-immutable-object-cache-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-immutable-object-cache-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mds-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mds-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mgr-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mgr-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mon-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-mon-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-osd-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-osd-debuginfo-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-radosgw-15.2.8.80+g1f4b6229ca-lp152.2.9.1

ceph-radosgw-debuginfo-15.2.8.80+g1f...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-27781.html

https://bugzilla.suse.com/1178860

https://bugzilla.suse.com/1179016

https://bugzilla.suse.com/1179802

https://bugzilla.suse.com/1180107

https://bugzilla.suse.com/1180155

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette

List Archives:

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:2327-1
Rating: important
Affected Products: openSUSE Leap 15.2 able.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here