Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2019:2049-1 Important: Ceph File Leak and Key Sanitization

suse
Calendar Grey August 5, 2019
Dist Suse Esm H88
SUSE has released a critical security update for ceph, providing essential corrections addressing important vulnerabilities across multiple components.
An update that solves two vulnerabilities and has 12 fixes is now available

Summary

This update for ceph fixes the following issues: Security issues fixed: - CVE-2019-3821: civetweb: fix file descriptor leak (bsc#1125080) - CVE-2018-16889: rgw: sanitize customer encryption keys from log output in v4 auth (bsc#1121567) Non-security issues fixed: - install grafana dashboards world readable (bsc#1136110) - upgrade results in cluster outage (bsc#1132396) - ceph status reports "HEALTH_WARN 3 monitors have not enabled msgr2" (bsc#1124957) - Dashboard: Opening tcmu-runner perf counters results in a 404 (bsc#1135388) - RadosGW stopped expiring objects (bsc#1133139) - Ceph does not recover when rebuilding every OSD (bsc#1133461) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1121567 #1123360 #1124957 #1125080 #1125899

#1131984 #1132396 #1133139 #1133461 #1135030

#1135219 #1135221 #1135388 #1136110

Cross- CVE-2018-16889 CVE-2019-3821

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

SUSE Enterprise Storage 6

https://www.suse.com/security/cve/CVE-2018-16889.html

https://www.suse.com/security/cve/CVE-2019-3821.html

https://bugzilla.suse.com/1121567

https://bugzilla.suse.com/1123360

https://bugzilla.suse.com/1124957

https://bugzilla.suse.com/1125080

https://bugzilla.suse.com/1125899

https://bugzilla.suse.com/1131984

https://bugzilla.suse.com/1132396

https://bugzilla.suse.com/1133139

https://bugzilla.suse.com/1133461

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2049-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here