Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph-ansible: hard coded credential in ceph-ansible playbook
(CVE-2020-1716)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgements, and other related information refer to the CVE
page(s) listed in the References section.
Bug Fix(es) and Enhancement(s):
For detailed information on changes in this release, see the Red Hat Ceph
Storage 4.1 Release Notes available at:
/release_notes/index
https://access.redhat.com/security/cve/CVE-2020-1716 https://access.redhat.com/security/updates/classification#important
Red Hat Ceph Storage 4.0 MON:
Source:
ceph-14.2.8-47.el7cp.src.rpm
noarch:
ceph-grafana-dashboards-14.2.8-47.el7cp.noarch.rpm
ceph-mgr-dashboard-14.2.8-47.el7cp.noarch.rpm
ceph-mgr-diskprediction-local-14.2.8-47.el7cp.noarch.rpm
ceph-mgr-k8sevents-14.2.8-47.el7cp.noarch.rpm
ceph-mgr-rook-14.2.8-47.el7cp.noarch.rpm
ppc64le:
ceph-base-14.2.8-47.el7cp.ppc64le.rpm
ceph-common-14.2.8-47.el7cp.ppc64le.rpm
ceph-debuginfo-14.2.8-47.el7cp.ppc64le.rpm
ceph-mgr-14.2.8-47.el7cp.ppc64le.rpm
ceph-mon-14.2.8-47.el7cp.ppc64le.rpm
ceph-selinux-14.2.8-47.el7cp.ppc64le.rpm
ceph-test-14.2.8-47.el7cp.ppc64le.rpm
libcephfs-devel-14.2.8-47.el7cp.ppc64le.rpm
libcephfs2-14.2.8-47.el7cp.ppc64le.rpm
librados-devel-14.2.8-47.el7cp.ppc64le.rpm
librados2-14.2.8-47.el7cp.ppc64le.rpm
libradospp-devel-14.2.8-47.el7cp.ppc64le.rpm
libradosstriper1-14.2.8-47.el7cp.ppc64le.rpm
librbd-devel-14.2.8-47.el7cp.ppc64le.rpm
librbd1-14.2.8-47.el7cp.ppc64le.rpm
librgw-devel-14.2.8-47.el7cp.ppc64le.rpm
librgw2-14.2.8-47.el7cp.ppc64le.rpm
python-ceph-argparse-14.2.8-47.el7cp.ppc64le.rpm
python-cephfs-14.2.8-47.el7cp.ppc64le.rpm
python-rados-14.2.8-47.el7cp.ppc64le.rpm
python-rbd-14.2.8-47.el7cp.ppc64le.rpm
python-rgw-14.2.8-47.el7cp.ppc64le.rpm
x86_64:
ceph-base-14.2.8-47.el7cp.x86_64.rpm
Read the Full Advisory
Red Hat Ceph Storage 4.1 is now available.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Ceph Storage 4.0 MON - noarch, ppc64le, x86_64
Red Hat Ceph Storage 4.1 MON - noarch, ppc64le, x86_64
Red Hat Ceph Storage 4.1 OSD - ppc64le, x86_64
Red Hat Ceph Storage 4.1 Tools - noarch, ppc64le, x86_64
1274084 - [RFE] Support for AWS Secure Token Service (STS) with RGW
1553202 - [RFE] Support user creation on secondary zone in multisite environment
1581421 - [RFE] If the nodeep-scrub/noscrub flags are set in pools instead of global cluster. List the pool names in the ceph status
1625951 - [GSS] Recursive move from a directory with double underscore fails
1639817 - RFE: S3 v2 RESTBucketGet
1656512 - [RFE] Single Sign-On (SAML 2.0)
1658491 - [iscsi] add mixed iscsi (ipv4+ipv6) gateways on a ipv4 ceph cluster
1665683 - RGW: presigned URL for PUT with metadata fails with: SignatureDoesNotMatch
1678701 - rgw: org.apache.hadoop.fs.contract.s3a.ITestS3AContractGetFileStatus#testComplexDirActions
1679924 - Add Bluestore compression stats in dashboard
1687971 - [RFE] Bucket Check Commands Should Only Display Error/Orphaned Objects
1716815 - [RFE] Supportability of VMware ESX 6.7 on using Ceph iSCSI gateway
1716972 - bucket listing may repeat some unicode names
1719446 - facing rgw error - "/builddir/build/BUILD/ceph-12.2.8/src/rgw/rgw_sync.cc: In function 'virtual int PurgePeriodLogsCR::operate()' thread 7efe125d1700 .. .../rgw_sync.cc: 2387: FAILED assert(cursor) "
1724428 - The "host" signature in "ceph osd status" remains unchanged on moving an OSD disk from failed node to a new node (workaround: mgr restart)
1731148 - multisite pg_num on site2 pools should use site1/source values
Get the latest Linux and open source security news straight to your inbox.