Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE 15-SP4: SUSE-SU-2022:2818-1 Critical: Ceph Security Issue

suse
Calendar Grey August 16, 2022
Dist Suse Esm H88
Important security patch rollout for Ceph on SUSE platforms tackling a major vulnerability and supplying essential corrections.
An update that solves one vulnerability, contains one feature and has 5 fixes is now available

Summary

This update for ceph fixes the following issues: - Update to 16.2.9-536-g41a9f9a5573: + (bsc#1195359, bsc#1200553) rgw: check bucket shard init status in RGWRadosBILogTrimCR + (bsc#1194131) ceph-volume: honour osd_dmcrypt_key_size option (CVE-2021-3979) - Update to 16.2.9-158-gd93952c7eea: + cmake: check for python(\d)\.(\d+) when building boost + make-dist: patch boost source to support python 3.10 - Update to ceph-16.2.9-58-ge2e5cb80063: + (bsc#1200064, pr#480) Remove last vestiges of docker.io image paths - Update to 16.2.9.50-g7d9f12156fb: + (jsc#SES-2515) High-availability NFS export + (bsc#1196044) cephadm: prometheus: The generatorURL in alerts is only using hostname + (bsc#1196785) cephadm: avoid crashing on expected non-zero exit - Update to 16.2.7-969-g6195a460d89

References

#1194131 #1195359 #1196044 #1196785 #1200064

#1200553 SES-2515

Cross- CVE-2021-3979

CVSS scores:

CVE-2021-3979 (SUSE): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Linux Enterprise Desktop 15-SP4

SUSE Linux Enterprise High Performance Computing 15-SP4

SUSE Linux Enterprise Module for Basesystem 15-SP4

SUSE Linux Enterprise Server 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15-SP4

SUSE Manager Proxy 4.3

SUSE Manager Retail Branch Server 4.3

SUSE Manager Server 4.3

openSUSE Leap 15.4

https://www.suse.com/security/cve/CVE-2021-3979.html

https://bugzilla.suse.com/1194131

https://bugzilla.suse.com/1195359

https://bugzilla.suse.com/1196044

https://bugzilla.suse.com/1196785

https://bugzilla.suse.com/1200064

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2818-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here