Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for ceph fixes the following issues: Security issues fixed: - CVE-2018-7262: rgw: malformed http headers can crash rgw (bsc#1081379). - CVE-2017-16818: User reachable asserts allow for DoS (bsc#1063014). Bug fixes: - bsc#1061461: OSDs keep generating coredumps after adding new OSD node to cluster. - bsc#1079076: RGW openssl fixes. - bsc#1067088: Upgrade to SES5 restarted all nodes, majority of OSDs aborts during start. - bsc#1056125: Some OSDs are down when doing performance testing on rbd image in EC Pool. - bsc#1087269: allow_ec_overwrites option not in command options list. - bsc#1051598: Fix mountpoint check for systemctl enable --runtime. - bsc#1070357: Zabbix mgr module doesn't recover from HEALTH_ERR. - bsc#1066502: After upgrading a single OSD from SES 4 to SES 5 the OSDs
#1051598 #1054061 #1056125 #1056967 #1059458
#1060904 #1061461 #1063014 #1066182 #1066502
#1067088 #1067119 #1067705 #1070357 #1071386
#1074301 #1079076 #1080788 #1081379 #1081600
#1086340 #1087269 #1087493
Cross- CVE-2017-16818 CVE-2018-7262
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP3
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Desktop 12-SP3
SUSE CaaS Platform ALL
https://www.suse.com/security/cve/CVE-2017-16818.html
https://www.suse.com/security/cve/CVE-2018-7262.html
https://bugzilla.suse.com/1051598
https://bugzilla.suse.com/1054061
https://bugzilla.suse.com/1056125
https://bugzilla.suse.com/1056967
https://bugzilla.suse.com/1059458
https://bugzilla.suse.com/1060904
https://bugzilla.suse.com/1061461
Get the latest Linux and open source security news straight to your inbox.