Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 137 articles for you...
203

Mageia 9 - MGASA-2025-0011: Critical Authentication Bypass in ceph

Authentication bypass in CEPH RadosGW. (CVE-2024-48916) References: - https://bugs.mageia.org/show_bug.cgi?id=33896 - https://ubuntu.com/security/notices/USN-7182-1 . MGASA-2025-0011 - Updated ceph packages fix security vulnerability Publication date: 14 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0011.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-48916 Authentication bypass in CEPH RadosGW. (CVE-2024-48916) References: - https://bugs.mageia.org/show_bug.cgi?id=33896 - https://ubuntu.com/security/notices/USN-7182-1 - https://www.cve.org/CVERecord?id=CVE-2024-48916 SRPMS: - 9/core/ceph-18.1.1-1.1.mga9 . Mageia 2025-0012 resolves a privilege escalation vulnerability in Ceph RadosGW. Discover essential details about the security updates.. Ceph Security, Mageia Updates, Authentication Bypass, Security Fix, Mageia Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 14, 2025 Critical Mageia
172

Ubuntu 24.10 LTS: USN-7182-1 critical: ceph unauthorized access

Ceph could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-7182-1 January 06, 2025 ceph vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Ceph could allow unintended access to network services. Software Description: - ceph: distributed storage and file system Details: It was discovered that Ceph incorrectly handled unsupported JWT algorithms in the RadosGW gateway. An attacker could possibly use this issue to bypass certain authentication checks and restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 ceph 19.2.0-0ubuntu2.1 ceph-base 19.2.0-0ubuntu2.1 ceph-common 19.2.0-0ubuntu2.1 radosgw 19.2.0-0ubuntu2.1 Ubuntu 24.04 LTS ceph 19.2.0-0ubuntu0.24.04.2 ceph-base 19.2.0-0ubuntu0.24.04.2 ceph-common 19.2.0-0ubuntu0.24.04.2 radosgw 19.2.0-0ubuntu0.24.04.2 Ubuntu 22.04 LTS ceph 17.2.7-0ubuntu0.22.04.2 ceph-base 17.2.7-0ubuntu0.22.04.2 ceph-common 17.2.7-0ubuntu0.22.04.2 radosgw 17.2.7-0ubuntu0.22.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7182-1 CVE-2024-48916 Package Information: https://launchpad.net/ubuntu/+source/ceph/19.2.0-0ubuntu2.1 . Kubernetes may expose services unexpectedly. Ensure you apply updates to your Debian systems for enhanced security against this vulnerability.. ceph security issue, unintended access, ubuntu advisory, network service vulnerability, software update instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 06, 2025 Critical Ubuntu
87

Debian Bookworm: DSA-5825-1 critical: Ceph authentication bypass

Sage McTaggart discovered an authentication bypass in radosgw, the RADOS REST gateway of Ceph, a distributed storage and file system. For the stable distribution (bookworm), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5825-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 06, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ceph CVE ID : CVE-2023-43040 CVE-2024-48916 Sage McTaggart discovered an authentication bypass in radosgw, the RADOS REST gateway of Ceph, a distributed storage and file system. For the stable distribution (bookworm), these problems have been fixed in version 16.2.15+ds-0+deb12u1. We recommend that you upgrade your ceph packages. For the detailed security status of ceph please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ceph Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Security vulnerability in Ceph RADOS gateway addressed in Debian stable version. Users urged to upgrade for enhanced protection.. Debian Security Advisory, Ceph Software Update, Authentication Bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 06, 2024 Critical Debian
89

Fedora 40: Advisory for Ceph 18.2.2 Update on Riscv64 Compatibility

ceph-18.2.2 GA Add support for riscv64. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-1c5e37820f 2024-03-23 00:20:56.399852 -------------------------------------------------------------------------------- Name : ceph Product : Fedora 40 Version : 18.2.2 Release : 1.fc40 URL : Summary : User space components of the Ceph file system Description : Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. -------------------------------------------------------------------------------- Update Information: ceph-18.2.2 GA Add support for riscv64 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 7 2024 Kaleb S. KEITHLEY - 2:18.2.2-1 - ceph-18.2.2 GA * Wed Mar 6 2024 David Abdurachmanov - 2:18.2.1-11 - Add support for riscv64 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1c5e37820f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest release of Ceph 18.2.2 for Fedora 40 introduces enhanced support for riscv64 architecture, boosting its storage functionalities significantly.. Fedora Ceph Update, Riscv64 Support, Distributed Storage, Open Source Storage. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Mar 23, 2024 Informational Fedora
91

Gentoo: GLSA-202312-10 High: Ceph Root Escalation Advisory

A vulnerability has been found in Ceph which can lead to root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202312-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Ceph: Root Privilege Escalation Date: December 23, 2023 Bugs: #878277 ID: 202312-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in Ceph which can lead to root privilege escalation. Background ========== Ceph is a distributed network file system designed to provide excellent performance, reliability, and scalability. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ sys-cluster/ceph < 17.2.6 > = 17.2.6 Description =========== A vulnerability has been discovered in Ceph. Please review the CVE identifier referenced below for details. Impact ====== The ceph-crash.service runs the ceph-crash Python script as root. The script is operating in the directory /var/lib/ceph/crash which is controlled by the unprivileged ceph user (ceph:ceph mode 0750). The script periodically scans for new crash directories and forwards the content via `ceph crash post`. Workaround ========== There is no known workaround at this time. Resolution ========== All Ceph users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/ceph-17.2.6" References ========== [ 1 ] CVE-2022-3650 https://nvd.nist.gov/vuln/detail/CVE-2022-3650 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202312-10 Concerns? ========= Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo's Ceph identifies a major vulnerability allowing root privilege escalation; users are urged to update promptly to ensure their systems are secure.. Gentoo Linux Advisory,Cep,Root Escalation,Upgrade Steps,Security Patch. . LinuxSecurity.com Team

Calendar%202 Dec 23, 2023 Gentoo
197

Debian 10 Buster DLA-3629-1 Moderate: Ceph Denial of Service Threats

Multiple vulnerabilities were fixed in Ceph, a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3629-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès October 23, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ceph Version : 12.2.11+dfsg1-2.1+deb10u1 CVE ID : CVE-2019-10222 CVE-2020-1700 CVE-2020-1760 CVE-2020-10753 CVE-2020-12059 CVE-2020-25678 CVE-2020-27781 CVE-2021-3524 CVE-2021-3531 CVE-2021-3979 CVE-2021-20288 CVE-2023-43040 Debian Bug : 1053690 Multiple vulnerabilities were fixed in Ceph, a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. CVE-2019-10222 A Denial of service was fixed: An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients. CVE-2020-1700 A Denial of Service was fixed: A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the exhaustion of available resources, preventing legitimate users from connecting to the system. CVE-2020-1760 A XSS attack was fixed: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potentialXSS attacks due to the lack of proper neutralization of untrusted input. CVE-2020-10753 A Header Injection attack was fixed: It was possible to inject HTTP headers via a CORS ExposeHeader tag in an Amazon S3 bucket. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. CVE-2020-12059 A Denial of Service was fixed: A POST request with an invalid tagging XML could crash the RGW process by triggering a NULL pointer exception. CVE-2020-25678 An Information Disclosure was fixed: ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. CVE-2020-27781 A Privilege Escalation was fixed: User credentials could be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. CVE-2021-3524 Similar to CVE-2020-10753, a Header Injection attack was fixed: It was possible to inject HTTP headers via a CORS ExposeHeader tag in an Amazon S3 bucket CVE-2021-3531 A Denial of Service was fixed: When processing a GET Request in Ceph Storage RGW for a swift URL that ends with two slashes it could cause the rgw to crash, resulting in a denial of service. CVE-2021-3979 A Loss of Confidentiality was fixed: A key length flaw was found in Ceph Storage. An attacker could exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, whichis weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. CVE-2021-20288 A Potential Privilege Escalation was fixed: When handling CEPHX_GET_PRINCIPAL_SESSION_KEY requests, ignore CEPH_ENTITY_TYPE_AUTH in CephXServiceTicketRequest::keys. CVE-2023-43040 A flaw was found in Ceph RGW. An unprivileged user can write to any bucket(s) accessible by a given key if a POST's form-data contains a key called 'bucket' with a value matching the name of the bucket used to sign the request. The result of this is that a user could actually upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in said POST form part. For Debian 10 buster, these problems have been fixed in version 12.2.11+dfsg1-2.1+deb10u1. We recommend that you upgrade your ceph packages. For the detailed security status of ceph please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ceph Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance security on your Debian server by upgrading Ceph packages after a security advisory. Update package lists and upgrade Ceph packages for safety.. Ceph Security Update, Debian LTS Advisory, Denial Of Service, Privilege Escalation. . LinuxSecurity.com Team

Calendar%202 Oct 23, 2023 Debian LTS
100

SUSE: 2023:3084-1 Important: Rook and Ceph Security Update

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:. SUSE Container Update Advisory: ses/7.1/rook/ceph ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3084-1 Container Tags : ses/7.1/rook/ceph:1.11.9 , ses/7.1/rook/ceph:1.11.9.0 , ses/7.1/rook/ceph:1.11.9.0.4.7.1 , ses/7.1/rook/ceph:latest , ses/7.1/rook/ceph:sle15.3.pacific Container Release : 4.7.1 Severity : important Type : security References : 1089497 1099269 1103893 1112183 1133277 1144068 1157881 1158763 1162343 1177127 1178168 1182066 1182142 1184753 1186673 1193412 1194530 1197726 1198165 1198331 1199282 1200710 1201627 1202234 1203681 1203750 1204072 1204256 1206627 1207534 1207805 1208721 1209229 1209279 1209536 1209565 1209859 1210740 1210999 1211078 1211079 1211158 1211261 1211419 1211661 1211674 1211828 1212126 1212187 1212187 1212222 1212260 1213004 1213008 1213189 1213231 1213282 1213487 1213504 1213514 1213517 1213557 1213582 1213582 1213673 1213853 1214025 1214052 1214054 1214071 1214248 1214290 1214768 CVE-2007-4559 CVE-2018-1000518 CVE-2020-25659 CVE-2020-36242 CVE-2021-22569 CVE-2021-22570 CVE-2022-1941 CVE-2022-3171 CVE-2022-41409 CVE-2022-4304 CVE-2023-22652 CVE-2023-2603 CVE-2023-30078 CVE-2023-30079 CVE-2023-31484 CVE-2023-32181 CVE-2023-32681 CVE-2023-3446 CVE-2023-34969 CVE-2023-36054 CVE-2023-3817 CVE-2023-38408 CVE-2023-39615 CVE-2023-4016 CVE-2023-4039 CVE-2023-4156 ----------------------------------------------------------------- The container ses/7.1/rook/ceph was updated. The following patches have been included in thisupdate: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2497-1 Released: Tue Jun 13 15:37:25 2023 Summary: Recommended update for libzypp Type: recommended Severity: important References: 1211661,1212187 This update for libzypp fixes the following issues: - Fix 'Curl error 92' when synchronizing SUSE Manager repositories. [bsc#1212187] - Do not unconditionally release a medium if provideFile failed. [bsc#1211661] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2517-1 Released: Thu Jun 15 07:09:52 2023 Summary: Security update for python3 Type: security Severity: moderate References: 1203750,1211158,CVE-2007-4559 This update for python3 fixes the following issues: - CVE-2007-4559: Fixed filter for tarfile.extractall (bsc#1203750). - Fixed unittest.mock.patch.dict returns function when applied to coroutines (bsc#1211158). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2625-1 Released: Fri Jun 23 17:16:11 2023 Summary: Recommended update for gcc12 Type: recommended Severity: moderate References: This update for gcc12 fixes the following issues: - Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204 * includes regression and other bug fixes - Speed up builds with --enable-link-serialization. - Update embedded newlib to version 4.2.0 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2742-1 Released: Fri Jun 30 11:40:56 2023 Summary: Recommended update for autoyast2, libzypp, yast2-pkg-bindings, yast2-update, zypper Type: recommended Severity: moderate References: 1202234,1209565,1211261,1212187,1212222 This update for yast2-pkg-bindings fixes the following issues: libzypp was updated to version 17.31.14 (22): - Curl: trim all custom headers (bsc#1212187) HTTP/2 RFC 9113 forbids fields ending with a space. So we make sure all custom headersare trimmed. This also includes headers returned by URL-Resolver plugins. - build: honor libproxy.pc's includedir (bsc#1212222) zypper was updated to version 1.14.61: - targetos: Add an error note if XPath:/product/register/target is not defined in /etc/products.d/baseproduct (bsc#1211261) - targetos: Update help and man page (bsc#1211261) yast2-pkg-bindings, autoyast: - Added a new option for rebuilding the RPM database (--rebuilddb) (bsc#1209565) - Selected products are not installed after resetting the package manager internally (bsc#1202234) yast2-update: - Rebuild the RPM database during upgrade (--rebuilddb) (bsc#1209565) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2783-1 Released: Tue Jul 4 22:08:19 2023 Summary: Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets Type: security Severity: important References: 1099269,1133277,1144068,1162343,1177127,1178168,1182066,1184753,1194530,1197726,1198331,1199282,1203681,1204256,CVE-2018-1000518,CVE-2020-25659,CVE-2020-36242,CVE-2021-22569,CVE-2021-22570,CVE-2022-1941,CVE-2022-3171 This update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests,python-websocket-client, python-websockets fixes the following issues: grpc: - Update in SLE-15 (bsc#1197726, bsc#1144068) protobuf: - Fix a potential DoS issue in protobuf-cpp and protobuf-python, CVE-2022-1941, bsc#1203681 - Fix a potential DoS issue when parsing with binary data in protobuf-java, CVE-2022-3171, bsc#1204256 - Fix potential Denial of Service in protobuf-java in the parsing procedure for binary data, CVE-2021-22569, bsc#1194530 - Add missing dependency of python subpackages on python-six (bsc#1177127) - Updated to version 3.9.2 (bsc#1162343) * Remove OSReadLittle* due to alignment requirements. * Don't use unions and instead use memcpy for the type swaps. - Disable LTO (bsc#1133277) python-aiocontextvars: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) python-avro: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) python-cryptography: - update to 3.3.2 (bsc#1182066, CVE-2020-36242, bsc#1198331) * SECURITY ISSUE: Fixed a bug where certain sequences of update() calls when symmetrically encrypting very large payloads (> 2GB) could result in an integer overflow, leading to buffer overflows. CVE-2020-36242 python-cryptography-vectors: - update to 3.2 (bsc#1178168, CVE-2020-25659): * CVE-2020-25659: Attempted to make RSA PKCS#1v1.5 decryption more constant time, to protect against Bleichenbacher vulnerabilities. Due to limitations imposed by our API, we cannot completely mitigate this vulnerability. * Support for OpenSSL 1.0.2 has been removed. * Added basic support for PKCS7 signing (including SMIME) via PKCS7SignatureBuilder. - update to 3.3.2 (bsc#1198331) python-Deprecated: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - update to 1.2.13: python-google-api-core: - Update to 1.14.2 python-googleapis-common-protos: - Update to 1.6.0 python-grpcio-gcp: - Initial spec for v0.2.2 python-humanfriendly: - Update in SLE-15 (bsc#1199282, jsc#PM-3243,jsc#SLE-24629) - Update to 10.0 python-jsondiff: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Update to version 1.3.0 python-knack: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Update to version 0.9.0 python-opencensus: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Disable Python2 build - Update to 0.8.0 python-opencensus-context: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) python-opencensus-ext-threading: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Initial build version 0.1.2 python-opentelemetry-api: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Version update to 1.5.0 python-psutil: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - update to 5.9.1 - remove the dependency on net-tools, since it conflicts with busybox-hostnmame which is default on MicroOS. (bsc#1184753) - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) python-PyGithub: - Update to 1.43.5: python-pytest-asyncio: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Initial release of python-pytest-asyncio 0.8.0 python-requests: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) python-websocket-client: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Update to version 1.3.2 python-websockets: - Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - update to 9.1: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2855-1 Released: Mon Jul 17 16:35:21 2023 Summary: Recommended update for openldap2 Type: recommended Severity: moderate References: 1212260 This update for openldap2 fixes the following issues: - libldap2 crashes on ldap_sasl_bind_s (bsc#1212260) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2866-1 Released: Tue Jul 18 11:09:03 2023 Summary: Security update for python-requests Type: security Severity: moderate References: 1211674,CVE-2023-32681 This update for python-requests fixes the following issues: - CVE-2023-32681: Fixed unintended leak of Proxy-Authorization header (bsc#1211674). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2879-1 Released: Wed Jul 19 09:45:34 2023 Summary: Security update for dbus-1 Type: security Severity: moderate References: 1212126,CVE-2023-34969 This update for dbus-1 fixes the following issues: - CVE-2023-34969: Fixed a possible dbus-daemon crash by an unprivileged users (bsc#1212126). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2882-1 Released: Wed Jul 19 11:49:39 2023 Summary: Security update for perl Type: security Severity: important References: 1210999,CVE-2023-31484 This update for perl fixes the following issues: - CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2885-1 Released: Wed Jul 19 16:58:43 2023 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1208721,1209229,1211828 This update for glibc fixes the following issues: - getlogin_r: fix missing fallback if loginuid is unset (bsc#1209229, BZ #30235) - Exclude static archives from preparation for live patching (bsc#1208721) - resolv_conf: release lock on allocation failure (bsc#1211828, BZ #30527) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2918-1 Released: Thu Jul 20 12:00:17 2023 Summary: Recommended update for gpgme Type: recommended Severity: moderate References: 1089497 This update for gpgme fixes the following issues: gpgme: - Address failure handling issues when using gpg 2.2.6 via gpgme, as used by libzypp (bsc#1089497) libassuan: - Version upgrade to 2.5.5 in LTSS to address gpgme newrequirements ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2945-1 Released: Mon Jul 24 09:37:30 2023 Summary: Security update for openssh Type: security Severity: important References: 1186673,1209536,1213004,1213008,1213504,CVE-2023-38408 This update for openssh fixes the following issues: - CVE-2023-38408: Fixed a condition where specific libaries loaded via ssh-agent(1)'s PKCS#11 support could be abused to achieve remote code execution via a forwarded agent socket if those libraries were present on the victim's system and if the agent was forwarded to an attacker-controlled system. [bsc#1213504, CVE-2023-38408] - Close the right filedescriptor and also close fdh in read_hmac to avoid file descriptor leaks. [bsc#1209536] - Attempts to mitigate instances of secrets lingering in memory after a session exits. [bsc#1186673, bsc#1213004, bsc#1213008] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2956-1 Released: Tue Jul 25 08:33:38 2023 Summary: Security update for libcap Type: security Severity: moderate References: 1211419,CVE-2023-2603 This update for libcap fixes the following issues: - CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2994-1 Released: Thu Jul 27 06:45:29 2023 Summary: Recommended update for nfs-utils Type: recommended Severity: moderate References: 1157881,1200710,1209859 This update for nfs-utils fixes the following issues: - SLE15-SP5 and earlier don't use /usr/lib/modprobe.d (bsc#1200710) - Avoid unhelpful warnings (bsc#1157881) - Fix rpc.nfsd man pages (bsc#1209859) - Allow scope to be set in sysconfig: NFSD_SCOPE ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3179-1 Released: Thu Aug 3 13:59:38 2023 Summary: Security updatefor openssl-1_1 Type: security Severity: moderate References: 1201627,1207534,1213487,CVE-2022-4304,CVE-2023-3446 This update for openssl-1_1 fixes the following issues: - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487). - Update further expiring certificates that affect tests [bsc#1201627] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3210-1 Released: Mon Aug 7 15:20:04 2023 Summary: Security update for pcre2 Type: security Severity: moderate References: 1213514,CVE-2022-41409 This update for pcre2 fixes the following issues: - CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3218-1 Released: Mon Aug 7 16:52:13 2023 Summary: Recommended update for cryptsetup Type: recommended Severity: moderate References: 1211079 This update for cryptsetup fixes the following issues: - Handle system with low memory and no swap space (bsc#1211079) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3284-1 Released: Fri Aug 11 10:29:50 2023 Summary: Recommended update for shadow Type: recommended Severity: moderate References: 1206627,1213189 This update for shadow fixes the following issues: - Prevent lock files from remaining after power interruptions (bsc#1213189) - Add --prefix support to passwd, chpasswd and chage (bsc#1206627) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3288-1 Released: Fri Aug 11 12:30:14 2023 Summary: Recommended update for python-apipkg Type: recommended Severity: moderate References: 1213582 This update for python-apipkg provides python3-apipkg to SUSE Linux Enterprise Micro 5.2. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3291-1 Released: Fri Aug 11 12:51:21 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213517,1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3330-1 Released: Wed Aug 16 08:59:33 2023 Summary: Recommended update for python-pyasn1 Type: recommended Severity: important References: 1207805 This update for python-pyasn1 fixes the following issues: - To avoid users of this package having to recompile bytecode files, change the mtime of any __init__.py. (bsc#1207805) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3365-1 Released: Fri Aug 18 20:35:01 2023 Summary: Security update for krb5 Type: security Severity: important References: 1214054,CVE-2023-36054 This update for krb5 fixes the following issues: - CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3388-1 Released: Wed Aug 23 17:14:22 2023 Summary: Recommended update for binutils Type: recommended Severity: important References: 1213282 This update for binutils fixes the following issues: - Add `binutils-disable-dt-relr.sh` to address compatibility problems with the glibc version included in future SUSE Linux Enterprise releases (bsc#1213282, jsc#PED-1435) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3440-1 Released: Mon Aug 28 08:57:102023 Summary: Security update for gawk Type: security Severity: low References: 1214025,CVE-2023-4156 This update for gawk fixes the following issues: - CVE-2023-4156: Fix a heap out of bound read by validating the index into argument list. (bsc#1214025) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3454-1 Released: Mon Aug 28 13:43:18 2023 Summary: Security update for ca-certificates-mozilla Type: security Severity: important References: 1214248 This update for ca-certificates-mozilla fixes the following issues: - Updated to 2.62 state of Mozilla SSL root CAs (bsc#1214248) Added: - Atos TrustedRoot Root CA ECC G2 2020 - Atos TrustedRoot Root CA ECC TLS 2021 - Atos TrustedRoot Root CA RSA G2 2020 - Atos TrustedRoot Root CA RSA TLS 2021 - BJCA Global Root CA1 - BJCA Global Root CA2 - LAWtrust Root CA2 (4096) - Sectigo Public Email Protection Root E46 - Sectigo Public Email Protection Root R46 - Sectigo Public Server Authentication Root E46 - Sectigo Public Server Authentication Root R46 - SSL.com Client ECC Root CA 2022 - SSL.com Client RSA Root CA 2022 - SSL.com TLS ECC Root CA 2022 - SSL.com TLS RSA Root CA 2022 Removed CAs: - Chambers of Commerce Root - E-Tugra Certification Authority - E-Tugra Global Root CA ECC v3 - E-Tugra Global Root CA RSA v3 - Hongkong Post Root CA 1 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3466-1 Released: Tue Aug 29 07:33:16 2023 Summary: Recommended update for icu Type: recommended Severity: moderate References: 1103893,1112183 This update for icu fixes the following issues: - Japanese era Reiwa (bsc#1112183, bsc#1103893, fate570, fate#325570, fate#325419) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3470-1 Released: Tue Aug 29 10:49:33 2023 Summary: Recommended update for parted Type: recommended Severity: low References: 1182142,1193412 This update for parted fixes the following issues: - fix null pointer dereference (bsc#1193412) - update mkpart options in manpage (bsc#1182142) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3472-1 Released: Tue Aug 29 10:55:16 2023 Summary: Security update for procps Type: security Severity: low References: 1214290,CVE-2023-4016 This update for procps fixes the following issues: - CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3487-1 Released: Tue Aug 29 14:28:35 2023 Summary: Recommended update for lvm2 Type: recommended Severity: moderate References: 1214071 This update for lvm2 fixes the following issues: - blkdeactivate calls wrong mountpoint cmd (bsc#1214071) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3515-1 Released: Fri Sep 1 15:54:25 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1158763,1210740,1213231,1213557,1213673 This update for libzypp, zypper fixes the following issues: - Fix occasional isue with downloading very small files (bsc#1213673) - Fix negative ZYPP_LOCK_TIMEOUT not waiting forever (bsc#1213231) - Fix OES synchronization issues when cookie file has mode 0600 (bsc#1158763) - Don't cleanup orphaned dirs if read-only mode was promised (bsc#1210740) - Revised explanation of --force-resolution in man page (bsc#1213557) - Print summary hint if policies were violated due to --force-resolution (bsc#1213557) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3521-1 Released: Tue Sep 5 08:56:45 2023 Summary: Recommended update for python-iniconfig Type: recommended Severity: moderate References: 1213582 This update for python-iniconfig provides python3-iniconfig to SUSE Linux Enterprise Micro 5.2. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3639-1 Released: Mon Sep 18 13:33:16 2023 Summary: Security update for libeconf Type: security Severity: moderate References: 1198165,1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 This update for libeconf fixes the following issues: Update to version 0.5.2. - CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078). - CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078) The following non-security bug was fixed: - Fixed parsing files correctly which have space characters AND none space characters as delimiters (bsc#1198165). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3661-1 Released: Mon Sep 18 21:44:09 2023 Summary: Security update for gcc12 Type: security Severity: important References: 1214052,CVE-2023-4039 This update for gcc12 fixes the following issues: - CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3698-1 Released: Wed Sep 20 11:01:15 2023 Summary: Security update for libxml2 Type: security Severity: important References: 1214768,CVE-2023-39615 This update for libxml2 fixes the following issues: - CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3720-1 Released: Thu Sep 21 09:01:11 2023 Summary: Recommended update for ceph-csi, csi-external-attacher, csi-external-provisioner, csi-external-resizer, csi-external-snapshotter, csi-node-driver-registrar, rook Type: recommended Severity: moderate References: 1204072,1209279 This update for ceph-csi, csi-external-attacher,csi-external-provisioner, csi-external-resizer, csi-external-snapshotter, csi-node-driver-registrar, rook fixes the following issues: - Update to v4.1.0 * Updated Kubernetes dependencies to 1.26.0 (#395, @sunnylovestiramisu) - Update version to 3.4.0 Feature * Add support for cross-namespace data sources alpha feature (#805, [@ttakahashi21] * Register metrics exposed by sig-storage-lib (#792, @RaunakShah) * Update the annotation that needs to be applies to VolumeSnapshotContents from snapshot.storage.kubernetes.io/allowVolumeModeChange to snapshot.storage.kubernetes.io/allow-volume-mode-change (#791, @RaunakShah) Bug or Regression * Fix string pointer comparison for source volume mode conversion (#793, @RaunakShah) * Fix nil pointer crash for PV without ClaimRef (#796, @zezaeoh) Uncategorized * Update go to 1.19 and dependencies for k8s v1.26.0 (#834, @sunnylovestiramisu) - Update to version 1.7.0 * Fix panic in recovery path if marking pvc as resize in progress fails (#246, @gnufied) - Update to version 6.2.1 Feature * Add --retry-crd-interval-max flag to the snapshot-controller in order to allow customization of CRD detection on startup. (#777, @mattcary) Uncategorized * Change webhook example to be compatible with TLS-type secrets. (#793, @haslersn) * Fixes an issue introduced by PR 793 by respecting the format of TLS-type secrets in the script. (#796, @haslersn) * Update go to v1.19 and kubernetes dependencies to 1.26.0. (#797, @sunnylovestiramisu) - Update to version 2.7.0 * Revert of #214, node-driver-registrar will create the path specified by --kubelet-registration-path (#247, @mauriciopoppe) - Regular upgrade bsc#1204072 - Update to 1.11.9 Rook v1.11.9 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * multus: Fix 'deletecollection' permission not present (#12437, @sudharsanomprakash) * dashboard: Remove deprecated kubernetes.io/ingress.class annotation (#12418, @Jeansen) *external: Make import script idempotent (#12417, @parth-gr) * exporter: Ignore failed deletion of service monitor (#12430, @travisn) * multus: Add config file for validation tool (#12396, @BlaineEXE) * object: Clarify success message when reconciling CephObjectStoreUser (#12406, @polyedre) * docs: Update storage architecture diagram (#12252, @galexrt) * operator: Add ceph image version label to PVC (#12372, @YZ775) * object : Add SSL ref in cephobjectstore user secret (#12341, @thotz) - Update to 1.11.8 Rook v1.11.8 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * helm: add EC Block Pool config in helm chart (#12324, @Javlopez) * pool: Add .mgr pool to the stretch cluster examples (#12360, @travisn) * nfs: Add Spec.Security.Kerberos.DomainName to the CRD to configure /etc/idmapd.conf (#12220, @spuiuk) * mgr: Removing unnecessary rook-ceph-mgr rbac entries (#12337, @rkachach) * core: typo in logs to print fullname of CephCluster (#12217, @takirala) * core: empty ceph-daemons-sock-dir for osd onPVC (#12299, @avanthakkar) * docs: prevent to delete other clusters data on cluster deletion (#12334, @satoru-takeuchi) * docs: improve external doc format (#12383, @parth-gr) * docs: Suggest qemu driver for minikube on apple silicon (#11722, @BlaineEXE) - Update to 1.11.7 Rook v1.11.7 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * core: Delete exporter resources if ceph version is not supported (#12271, @avanthakkar) * external: FQDN should be persisted instead of using the ip endpoint (#12264, @parth-gr) * object: Implement more capabilities for object store users (#12256, @thotz) * test: Add CI e2e test for multus validation test (#12282, @BlaineEXE) * core: Use default-* logging flags for ceph daemons so they can be overridden (#12302, @Javlopez) * helm: Add exporter resource entry to ceph cluster documentation (#12251, @galexrt) * mgr: Allow othernamespaces in the ServiceMonitor resource (#12293, @kerryeon) * object: Add missing cephcluster spec addition in object controller (#12273, @thotz) * monitoring: Service monitor should not use mgr_role label (#12268, @travisn) * test: Allow specifying custom nginx image for multus validation (#12231, @iPraveenParihar) * operator: Pull multus validation test images before test (#12211, @BlaineEXE) * rbdmirror: Ensure rbd mirror daemon is upgraded (#12247, @travisn) - Update to 1.11.6 Rook v1.11.6 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * osd: Support expanding lvm osd on pvc (#12164, @satoru-takeuchi) * monitoring: Skip creating the service monitor for the exporter if monitoring is not enabled (#12216, @travisn) * docs: Generate documentation for CRDs (#12110 #12179, @Javlopez) * core: Add termination grace period for exporter pods (#12215, @avanthakkar) * csi: servicemonitor for rook-ceph csi drivers (#12170, @jouve) * monitoring: Configurable option to disable prometheus metrics (#12193, @travisn) * mgr: Default to active mgr label if only one mgr is running (#12137, @travisn) * osd: Allow scanning devices with filter (#11976, @Javlopez) * core: Disable controller runtime metrics server (#12194, @Madhu-1) * mgr: Use mgr_role dynamic label to tag the active ceph manager (#11845, @rkachach) * operator: use KUBECONFIG context for cli if present (#12192, @BlaineEXE) * external: fix rgw multisite config check (#12182 #12238, @parth-gr) * operator: validate multus validation networks in cli (#12187, @BlaineEXE) * operator: Fix package logger name for rookcli (#12186, @BlaineEXE) * ceph: Unset the encryption configuration before updating the setting (#12181, @Madhu-1) - Update to 1.11.5 Rook v1.11.5 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * mgr: Retry creating ceph dashboard credentials (#12149, @parth-gr) * nfs: Reduce size CephNFSCRD from unnecessary file volume sources (#12155, @BlaineEXE) * core: Update k8s API references to more recent version (#12161, @subhamkrai) * test: Add multus validation test routine to rook binary (#12069, @BlaineEXE) * external: check that the pool and cluster name is provided (#12132, @parth-gr) * core: Skip OBC controllers if not needed based (#12075, @sp98) * Add an ingress for Ceph object stores (#12109, @jouve) * core: Disable the exporter service (#12118, @avanthakkar) * nfs: Fixes for mounting CephNFS using Kerberos auth (#12086, @spuiuk) - Update to 1.11.4 Rook v1.11.4 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * core: Update default image to Ceph v17.2.6 (#12068, @travisn) * core: Disable the Ceph exporter daemon (#12077, @avanthakkar) * helm: Add option to scale down rook operator (#12048, @TomHellier) * helm: Drop snapshot.storage.k8s.io/v1beta1 (#12051, @sathieu) * external: Add support for RGW multisite in external cluster script (#12037, @parth-gr) * external: Do not require the monitoring endpoint (#12061, @neoaggelos) * external: Allow creating pools with special characters in name (#12056, @parth-gr) * external: Do not enforce rbd, cephfs and rgw flags for the external cluster (#12028, @parth-gr) * core: Use cluster ID for ns lookup on exported multi-cluster service (#12064, @sp98) * docs: Add scenario for deleted namespace to the disaster recovery guide (#11895, @gaord) * mgr: Failed to update the port of dashboard (#11932, @zhucan) - Update to 1.11.3 Rook v1.11.3 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * csi: Make AttachRequired as configurable for RWX volumes (#11899, @Madhu-1) * nfs: Add support for nfs-ganesha metrics monitoring (#12007, @synarete) * mgr: Add option to disable the prometheus mgr module (#11980, @thenamehasbeentake) * object: Check OBC provisioner for bucket notification (#11975, @thotz) *external: Make rgw call separate from cephfs and rbd in export script (#11947, @parth-gr) * core: Update vault pkg to 1.13.1 (#12013, @subhamkrai) * core: Fix config format for msgr2 ipv6 monitors (#11993, @heliochronix) * osd: Handle global or node-local device class configuration correctly (#11966, @satoru-takeuchi) * csi: IPv6 compatibility for requiring msgr2 (#11992, @travisn) * mon: Remove condition to use 6790 mon port (#11963, @sp98) - Update to 1.11.2 Rook v1.11.2 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * osd: Implemented encryption key rotation (#11749, @Rakshith-R) * core: Remove unnecessary ceph-conf-dir volume mount from exporter (#11950, @avanthakkar) * core: Set key rotation default in code instead of in CRDs (#11951, @travisn) * external: Use f-strings for formatting (#11944, @Sheetalpamecha) * core: Use msgr2 if compression is enabled (#11928, @uhthomas) * ci: Skip building csv on arm64 (#11906, @subhamkrai) * osd: Validate and remove duplicate topology labels (#11823, @parth-gr) * rgw: RGW dashboard can be disabled in the object CR (#11908, @thenamehasbeentake) * external: Pool and metadata EC pools were reversed in scripts (#11919, @dragon2611) * rgw: Skip objectstore name length validation when cluster is external (#11911, @parth-gr) * nfs: Network mode can be set separately for cephcluster and nfs (#11777, @taxilian) * csi: Update port to 3300 if msgr2 is required (#11859, @travisn) * core: Add FSID to the additionalPrinterColumns on cephcluster CRD (#11864, @thenamehasbeentake) * core: Add missing labels in exporter deployment (#11866, @avanthakkar) - Update to 1.11.1 Rook v1.11.1 is a patch release limited in scope and focusing on feature additions and bug fixes to the Ceph operator. * ceph: Fix host networking by only adding OSD ports when required for multi-cluster config (#11797, @sp98) * core: Ceph exporter requires ceph config where OSDs are not running (#11848,@avanthakkar) * monitoring: Remove prometheus alerts that don't apply to rook (#11842, @travisn) * mgr: Revert readiness probe and go back to the original sidecar HA implementation (#11829, @rkachach) * manifest: Align whitespace in example cluster.yaml (#11804, @gauravsitlani) * external: Add realm support for external cluster (#11584, @parth-gr) * object: Make OBC genUserID unique across clusters (#11665, @BlaineEXE) * file: Check if a filesystem exists before checking dependencies during deletion (#11221, @zhucan) * core: On crash pod ensure rook version label is not set (#11760, @gaord) - Update to 1.11.0 Breaking Changes * The minimum version of K8s version supported is v1.21. * The minimum version of the Ceph-CSI driver is v3.7. * Removed support for MachineDisruptionBudgets, including settings removed from the CephCluster CR: * manageMachineDisruptionBudgets * machineDisruptionBudgetNamespace * Versions of golang supported during development are v1.19 and v1.20. Features * Ceph-CSI v3.8 is now the version deployed by default with Rook. The driver has a number of important updates to add more storage features available to clients. * Added setting requireMsgr2 on the CephCluster CR to allow clusters with a kernel of 5.11 or newer to fully communicate with msgr2 and disable the msgr1 port. This allows for more flexibility to enable msgr2 features such as encryption and compression on the wire. * Change pspEnable default value to false in helm charts, and remove documentation for enabling PSP. If still using a version of K8s where PSPs are required, see the v1.10 documentation. * Object store bucket notifications and topics are now marked as stable features. * The Ceph exporter daemon is configured as the source of metrics based on performance counters from Ceph daemons. The exporter daemon provides more scalability of metrics collection to reduce load on the Ceph mgr. * Read affinity for RBD volumes is now available, leveraging the krbd mapoptions to allow serving reads from an OSD in proximity to the client, according to OSD locations defined in the CRUSH map and topology labels on nodes. * Mirroring data across clusters with overlapping networks is now supported. Mon and OSD services will be configured with global IPs across multiple clusters with overlapping CIDRs. The clusters must be configured using an MCS API-compatible applications such as submariner globalnet. This feature is supported for Ceph version v17.2.6 or later. * The Ceph Mgr standby now is managed with a readiness probe instead of a sidecar. Note that the standby mgr is expected to fail the readiness probe, while the active mgr passes the readiness probe. The following package changes have been done: - binutils-2.39-150100.7.43.2 updated - ca-certificates-mozilla-2.62-150200.30.1 updated - cryptsetup-2.3.7-150300.3.8.1 updated - dbus-1-1.12.2-150100.8.17.1 updated - device-mapper-2.03.05_1.02.163-150200.8.52.1 updated - gawk-4.2.1-150000.3.3.1 updated - glibc-locale-base-2.31-150300.52.2 updated - glibc-2.31-150300.52.2 updated - krb5-1.19.2-150300.13.1 updated - libassuan0-2.5.5-150000.4.5.2 updated - libcap2-2.26-150000.4.9.1 updated - libcryptsetup12-hmac-2.3.7-150300.3.8.1 updated - libcryptsetup12-2.3.7-150300.3.8.1 updated - libctf-nobfd0-2.39-150100.7.43.2 updated - libctf0-2.39-150100.7.43.2 updated - libdbus-1-3-1.12.2-150100.8.17.1 updated - libdevmapper-event1_03-2.03.05_1.02.163-150200.8.52.1 updated - libdevmapper1_03-2.03.05_1.02.163-150200.8.52.1 updated - libeconf0-0.5.2-150300.3.11.1 updated - libgcc_s1-12.3.0+git1204-150000.1.16.1 updated - libicu-suse65_1-65.1-150200.4.8.1 updated - libicu65_1-ledata-65.1-150200.4.8.1 updated - libldap-2_4-2-2.4.46-150200.14.17.1 updated - libldap-data-2.4.46-150200.14.17.1 updated - liblvm2cmd2_03-2.03.05-150200.8.52.1 updated - libopenssl1_1-hmac-1.1.1d-150200.11.75.1 updated - libopenssl1_1-1.1.1d-150200.11.75.1 updated - libparted0-3.2-150300.21.3.1 updated - libpcre2-8-0-10.31-150000.3.15.1updated - libprocps7-3.3.15-150000.7.34.1 updated - libprotobuf-lite20-3.9.2-150200.4.21.1 updated - libpython3_6m1_0-3.6.15-150300.10.48.1 updated - libsolv-tools-0.7.24-150200.20.2 updated - libstdc++6-12.3.0+git1204-150000.1.16.1 updated - libxml2-2-2.9.7-150000.3.60.1 updated - libzypp-17.31.20-150200.75.1 updated - login_defs-4.8.1-150300.4.9.1 updated - lvm2-2.03.05-150200.8.52.1 updated - nfs-client-2.1.1-150100.10.37.1 updated - nfs-kernel-server-2.1.1-150100.10.37.1 updated - openssh-clients-8.4p1-150300.3.22.1 updated - openssh-common-8.4p1-150300.3.22.1 updated - openssh-fips-8.4p1-150300.3.22.1 updated - openssh-server-8.4p1-150300.3.22.1 updated - openssh-8.4p1-150300.3.22.1 updated - openssl-1_1-1.1.1d-150200.11.75.1 updated - parted-3.2-150300.21.3.1 updated - perl-base-5.26.1-150300.17.14.1 updated - procps-3.3.15-150000.7.34.1 updated - python3-apipkg-1.4-150000.3.6.1 updated - python3-base-3.6.15-150300.10.48.1 updated - python3-curses-3.6.15-150300.10.48.1 updated - python3-iniconfig-1.1.1-150000.1.11.1 updated - python3-pyasn1-0.4.2-150000.3.5.1 updated - python3-requests-2.24.0-150300.3.3.1 updated - python3-websocket-client-1.3.2-150100.6.7.3 updated - python3-3.6.15-150300.10.48.1 updated - rook-k8s-yaml-1.11.9+git0.483b15e2-150300.3.9.1 updated - rook-1.11.9+git0.483b15e2-150300.3.9.1 updated - shadow-4.8.1-150300.4.9.1 updated - zypper-1.14.63-150200.59.1 updated - container:sles15-image-15.0.0-17.20.185 updated . Patch releases for SUSE Kubernetes, focusing on urgent vulnerabilities in the etcd and kubelet modules. Maintain your safety!. SUSE Container Update, Security Update, Rook, Ceph, Critical Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 21, 2023 Important SuSE
100

SUSE: 2023:3081-1 Important: Prometheus Node Exporter Security Fix

The container ses/7.1/ceph/prometheus-node-exporter was updated. The following patches have been included in this update:. SUSE Container Update Advisory: ses/7.1/ceph/prometheus-node-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3081-1 Container Tags : ses/7.1/ceph/prometheus-node-exporter:1.5.0 , ses/7.1/ceph/prometheus-node-exporter:1.5.0.3.2.516 , ses/7.1/ceph/prometheus-node-exporter:latest , ses/7.1/ceph/prometheus-node-exporter:sle15.3.pacific Container Release : 3.2.516 Severity : important Type : security References : 1089497 1158763 1198165 1201627 1202234 1206627 1207534 1208721 1209229 1209565 1210740 1210999 1211078 1211261 1211419 1211661 1211828 1212187 1212187 1212222 1212260 1213189 1213231 1213487 1213517 1213557 1213673 1213853 1214052 1214054 1214290 1214768 CVE-2022-4304 CVE-2023-22652 CVE-2023-2603 CVE-2023-30078 CVE-2023-30079 CVE-2023-31484 CVE-2023-32181 CVE-2023-3446 CVE-2023-36054 CVE-2023-3817 CVE-2023-39615 CVE-2023-4016 CVE-2023-4039 ----------------------------------------------------------------- The container ses/7.1/ceph/prometheus-node-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2497-1 Released: Tue Jun 13 15:37:25 2023 Summary: Recommended update for libzypp Type: recommended Severity: important References: 1211661,1212187 This update for libzypp fixes the following issues: - Fix 'Curl error 92' when synchronizing SUSE Manager repositories. [bsc#1212187] - Do not unconditionally release a medium if provideFile failed. [bsc#1211661] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2625-1 Released: Fri Jun 23 17:16:112023 Summary: Recommended update for gcc12 Type: recommended Severity: moderate References: This update for gcc12 fixes the following issues: - Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204 * includes regression and other bug fixes - Speed up builds with --enable-link-serialization. - Update embedded newlib to version 4.2.0 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2742-1 Released: Fri Jun 30 11:40:56 2023 Summary: Recommended update for autoyast2, libzypp, yast2-pkg-bindings, yast2-update, zypper Type: recommended Severity: moderate References: 1202234,1209565,1211261,1212187,1212222 This update for yast2-pkg-bindings fixes the following issues: libzypp was updated to version 17.31.14 (22): - Curl: trim all custom headers (bsc#1212187) HTTP/2 RFC 9113 forbids fields ending with a space. So we make sure all custom headers are trimmed. This also includes headers returned by URL-Resolver plugins. - build: honor libproxy.pc's includedir (bsc#1212222) zypper was updated to version 1.14.61: - targetos: Add an error note if XPath:/product/register/target is not defined in /etc/products.d/baseproduct (bsc#1211261) - targetos: Update help and man page (bsc#1211261) yast2-pkg-bindings, autoyast: - Added a new option for rebuilding the RPM database (--rebuilddb) (bsc#1209565) - Selected products are not installed after resetting the package manager internally (bsc#1202234) yast2-update: - Rebuild the RPM database during upgrade (--rebuilddb) (bsc#1209565) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2855-1 Released: Mon Jul 17 16:35:21 2023 Summary: Recommended update for openldap2 Type: recommended Severity: moderate References: 1212260 This update for openldap2 fixes the following issues: - libldap2 crashes on ldap_sasl_bind_s (bsc#1212260) ----------------------------------------------------------------- Advisory ID:SUSE-SU-2023:2882-1 Released: Wed Jul 19 11:49:39 2023 Summary: Security update for perl Type: security Severity: important References: 1210999,CVE-2023-31484 This update for perl fixes the following issues: - CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2885-1 Released: Wed Jul 19 16:58:43 2023 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1208721,1209229,1211828 This update for glibc fixes the following issues: - getlogin_r: fix missing fallback if loginuid is unset (bsc#1209229, BZ #30235) - Exclude static archives from preparation for live patching (bsc#1208721) - resolv_conf: release lock on allocation failure (bsc#1211828, BZ #30527) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2918-1 Released: Thu Jul 20 12:00:17 2023 Summary: Recommended update for gpgme Type: recommended Severity: moderate References: 1089497 This update for gpgme fixes the following issues: gpgme: - Address failure handling issues when using gpg 2.2.6 via gpgme, as used by libzypp (bsc#1089497) libassuan: - Version upgrade to 2.5.5 in LTSS to address gpgme new requirements ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2956-1 Released: Tue Jul 25 08:33:38 2023 Summary: Security update for libcap Type: security Severity: moderate References: 1211419,CVE-2023-2603 This update for libcap fixes the following issues: - CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3179-1 Released: Thu Aug 3 13:59:38 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1201627,1207534,1213487,CVE-2022-4304,CVE-2023-3446 This update for openssl-1_1 fixes the following issues: - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487). - Update further expiring certificates that affect tests [bsc#1201627] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3284-1 Released: Fri Aug 11 10:29:50 2023 Summary: Recommended update for shadow Type: recommended Severity: moderate References: 1206627,1213189 This update for shadow fixes the following issues: - Prevent lock files from remaining after power interruptions (bsc#1213189) - Add --prefix support to passwd, chpasswd and chage (bsc#1206627) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3291-1 Released: Fri Aug 11 12:51:21 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213517,1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3365-1 Released: Fri Aug 18 20:35:01 2023 Summary: Security update for krb5 Type: security Severity: important References: 1214054,CVE-2023-36054 This update for krb5 fixes the following issues: - CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3472-1 Released: Tue Aug 29 10:55:16 2023 Summary: Security update for procps Type: security Severity: low References: 1214290,CVE-2023-4016 Thisupdate for procps fixes the following issues: - CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3515-1 Released: Fri Sep 1 15:54:25 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1158763,1210740,1213231,1213557,1213673 This update for libzypp, zypper fixes the following issues: - Fix occasional isue with downloading very small files (bsc#1213673) - Fix negative ZYPP_LOCK_TIMEOUT not waiting forever (bsc#1213231) - Fix OES synchronization issues when cookie file has mode 0600 (bsc#1158763) - Don't cleanup orphaned dirs if read-only mode was promised (bsc#1210740) - Revised explanation of --force-resolution in man page (bsc#1213557) - Print summary hint if policies were violated due to --force-resolution (bsc#1213557) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3639-1 Released: Mon Sep 18 13:33:16 2023 Summary: Security update for libeconf Type: security Severity: moderate References: 1198165,1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 This update for libeconf fixes the following issues: Update to version 0.5.2. - CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078). - CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078) The following non-security bug was fixed: - Fixed parsing files correctly which have space characters AND none space characters as delimiters (bsc#1198165). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3661-1 Released: Mon Sep 18 21:44:09 2023 Summary: Security update for gcc12 Type: security Severity: important References: 1214052,CVE-2023-4039 This update for gcc12 fixes the following issues: - CVE-2023-4039: Fixed incorrect stackprotector for C99 VLAs on Aarch64 (bsc#1214052). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3698-1 Released: Wed Sep 20 11:01:15 2023 Summary: Security update for libxml2 Type: security Severity: important References: 1214768,CVE-2023-39615 This update for libxml2 fixes the following issues: - CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768). The following package changes have been done: - glibc-2.31-150300.52.2 updated - krb5-1.19.2-150300.13.1 updated - libassuan0-2.5.5-150000.4.5.2 updated - libcap2-2.26-150000.4.9.1 updated - libeconf0-0.5.2-150300.3.11.1 updated - libgcc_s1-12.3.0+git1204-150000.1.16.1 updated - libldap-2_4-2-2.4.46-150200.14.17.1 updated - libldap-data-2.4.46-150200.14.17.1 updated - libopenssl1_1-hmac-1.1.1d-150200.11.75.1 updated - libopenssl1_1-1.1.1d-150200.11.75.1 updated - libprocps7-3.3.15-150000.7.34.1 updated - libprotobuf-lite20-3.9.2-150200.4.21.1 updated - libsolv-tools-0.7.24-150200.20.2 updated - libstdc++6-12.3.0+git1204-150000.1.16.1 updated - libxml2-2-2.9.7-150000.3.60.1 updated - libzypp-17.31.20-150200.75.1 updated - login_defs-4.8.1-150300.4.9.1 updated - openssl-1_1-1.1.1d-150200.11.75.1 updated - perl-base-5.26.1-150300.17.14.1 updated - procps-3.3.15-150000.7.34.1 updated - shadow-4.8.1-150300.4.9.1 updated - zypper-1.14.63-150200.59.1 updated - container:sles15-image-15.0.0-17.20.185 updated . Important security enhancements for the ses/7.1/ceph/prometheus-node-exporter image containing vital fixes.. SUSE Update, Ceph Security, Prometheus Node Exporter, Container Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 21, 2023 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200