=========================================================================Ubuntu Security Notice USN-4304-1
March 17, 2020

ceph vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.10
- Ubuntu 18.04 LTS

Summary:

Ceph could be made to stop responding if it received specially crafted
network traffic.

Software Description:
- ceph: distributed storage and file system

Details:

Or Friedman discovered that Ceph incorrectly handled disconnects. A remote
authenticated attacker could possibly use this issue to cause Ceph to
consume resources, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
  ceph                            14.2.4-0ubuntu0.19.10.2
  ceph-base                       14.2.4-0ubuntu0.19.10.2
  ceph-common                     14.2.4-0ubuntu0.19.10.2

Ubuntu 18.04 LTS:
  ceph                            12.2.12-0ubuntu0.18.04.5
  ceph-base                       12.2.12-0ubuntu0.18.04.5
  ceph-common                     12.2.12-0ubuntu0.18.04.5

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4304-1
  CVE-2020-1700

Package Information:
  https://launchpad.net/ubuntu/+source/ceph/14.2.4-0ubuntu0.19.10.2
  https://launchpad.net/ubuntu/+source/ceph/12.2.12-0ubuntu0.18.04.5

Ubuntu 4304-1: Ceph vulnerability

March 17, 2020
Ceph could be made to stop responding if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: ceph 14.2.4-0ubuntu0.19.10.2 ceph-base 14.2.4-0ubuntu0.19.10.2 ceph-common 14.2.4-0ubuntu0.19.10.2 Ubuntu 18.04 LTS: ceph 12.2.12-0ubuntu0.18.04.5 ceph-base 12.2.12-0ubuntu0.18.04.5 ceph-common 12.2.12-0ubuntu0.18.04.5 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4304-1

CVE-2020-1700

Severity
March 17, 2020

Package Information

https://launchpad.net/ubuntu/+source/ceph/14.2.4-0ubuntu0.19.10.2 https://launchpad.net/ubuntu/+source/ceph/12.2.12-0ubuntu0.18.04.5

Related News