Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:2736-1 Moderate: Ceph And Ceph-Iscsi Security Update

suse
Calendar Grey October 22, 2019
Dist Suse Esm H88
SUSE has released a security update targeting a medium-severity vulnerability in the ceph and ceph-iscsi components, providing essential corrections.
An update that solves one vulnerability and has 21 fixes is now available

Summary

This update for ceph, ceph-iscsi and ses-manual_en fixes the following issues: Security issues fixed: - CVE-2019-10222: Fixed RGW crash caused by unauthenticated clients. (bsc#1145093) Non-security issues-fixed: - ceph-volume: prints errors to stdout with --format json (bsc#1132767) - mgr/dashboard: Changing rgw-api-host does not get effective without disable/enable dashboard mgr module (bsc#1137503) - mgr/dashboard: Silence Alertmanager alerts (bsc#1141174) - mgr/dashboard: Fix e2e failures caused by webdriver version (bsc#1145759) - librbd: always try to acquire exclusive lock when removing image (bsc#1149093) - The no{up,down,in,out} related commands have been revamped (bsc#1151990) - radosgw-admin gets two new subcommands for managing expire-stale objects. (bsc#1151991)

References

#1132767 #1134444 #1135584 #1137503 #1140491

#1141174 #1145093 #1145617 #1145618 #1145759

#1146656 #1147132 #1149093 #1150406 #1151439

#1151990 #1151991 #1151992 #1151993 #1151994

#1151995 #1152002

Cross- CVE-2019-10222

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

SUSE Enterprise Storage 6

https://www.suse.com/security/cve/CVE-2019-10222.html

https://bugzilla.suse.com/1132767

https://bugzilla.suse.com/1134444

https://bugzilla.suse.com/1135584

https://bugzilla.suse.com/1137503

https://bugzilla.suse.com/1140491

https://bugzilla.suse.com/1141174

https://bugzilla.suse.com/1145093

https://bugzilla.suse.com/1145617

https://bugzilla.suse.com/1145618

Announcement ID: SUSE-SU-2019:2736-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here