Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Enterprise Storage: SUSE-SU-2018:1576-1 Important: Ceph DoS

suse
Calendar Grey June 7, 2018
Scroller Suse
Crucial SUSE security patch for ceph mitigates denial of service vulnerabilities and introduces 9 further enhancements aimed at optimizing performance.
An update that solves one vulnerability and has 9 fixes is now available

Summary

This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357)

References

#1070357 #1071386 #1074301 #1079076 #1080788

#1081379 #1081600 #1086340 #1087269 #1087493

Cross- CVE-2018-7262

Affected Products:

SUSE Enterprise Storage 5

https://www.suse.com/security/cve/CVE-2018-7262.html

https://bugzilla.suse.com/1070357

https://bugzilla.suse.com/1071386

https://bugzilla.suse.com/1074301

https://bugzilla.suse.com/1079076

https://bugzilla.suse.com/1080788

https://bugzilla.suse.com/1081379

https://bugzilla.suse.com/1081600

https://bugzilla.suse.com/1086340

https://bugzilla.suse.com/1087269

https://bugzilla.suse.com/1087493

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1576-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.