Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE Enterprise Storage 6: 2021:1472-1 Critical Ceph and Deepsea Fixes

An update that solves three vulnerabilities and has 16 fixes is now available. . SUSE Security Update: Security update for ceph, deepsea ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1472-1 Rating: important References: #1145463 #1174466 #1177200 #1178016 #1178216 #1178235 #1178657 #1178837 #1178860 #1178905 #1179997 #1180118 #1180594 #1181183 #1181378 #1181665 #1183074 #1183487 #1183600 Cross-References: CVE-2020-25678 CVE-2020-27839 CVE-2021-20288 CVSS scores: CVE-2020-25678 (NVD) : 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2020-27839 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2021-20288 (NVD) : 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-20288 (SUSE): 8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: SUSE Enterprise Storage 6 ______________________________________________________________________________ An update that solves three vulnerabilities and has 16 fixes is now available. Description: This update for ceph, deepsea fixes the following issues: - ceph was updated to 14.2.20-402-g6aa76c6815: * CVE-2021-20288: Fixed unauthorized global_id reuse (bsc#1183074). * CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905). * CVE-2020-27839: Use secure cookies to store JWT Token (bsc#1179997). * mgr/dashboard: prometheus alerting: add some leeway for package drops and errors (bsc#1145463) * mon: have 'mon stat' output json as well (bsc#1174466) * rpm: ceph-mgr-dashboard recommends python3-saml on SUSE (bsc#1177200) * mgr/dashboard: Display a warning message in Dashboard when debug mode is enabled (bsc#1178235) * rgw: cls/user: set from_index for reset statscalls (bsc#1178837) * mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860) * bluestore: provide a different name for fallback allocator (bsc#1180118) * test/run-cli-tests: use cram from github (bsc#1181378) * mgr/dashboard: fix "Python2 Cookie module import fails on Python3" (bsc#1183487) * common: make ms_bind_msgr2 default to 'false' (bsc#1180594) - deapsea was updated to 0.9.35 * osd: add method to zap simple osds (bsc#1178657, bsc#1178216) * upgrade to cephadm: fix Drive Group generation (bsc#1181665) * Rework config change detection to handle global.conf correctly (bsc#1181183) * Use -i to pass credentials to `ceph dashboard` commands (bsc#1183600) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-1472=1 Package List: - SUSE Enterprise Storage 6 (noarch): deepsea-0.9.35+git.0.5a1dc9fe-3.34.1 deepsea-cli-0.9.35+git.0.5a1dc9fe-3.34.1 References: https://www.suse.com/security/cve/CVE-2020-25678.html https://www.suse.com/security/cve/CVE-2020-27839.html https://www.suse.com/security/cve/CVE-2021-20288.html https://bugzilla.suse.com/1145463 https://bugzilla.suse.com/1174466 https://bugzilla.suse.com/1177200 https://bugzilla.suse.com/1178016 https://bugzilla.suse.com/1178216 https://bugzilla.suse.com/1178235 https://bugzilla.suse.com/1178657 https://bugzilla.suse.com/1178837 https://bugzilla.suse.com/1178860 https://bugzilla.suse.com/1178905 https://bugzilla.suse.com/1179997 https://bugzilla.suse.com/1180118 https://bugzilla.suse.com/1180594 https://bugzilla.suse.com/1181183 https://bugzilla.suse.com/1181378 https://bugzilla.suse.com/1181665 https://bugzilla.suse.com/1183074 https://bugzilla.suse.com/1183487 https://bugzilla.suse.com/1183600 . Tackling essential updates for ceph and deepsea, specifically targeting vulnerabilities linked to the access of sensitive data and problems with user authorization.. Ceph Security Fixes, Deepsea Security Update, SUSE Patch, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 04, 2021 Important SuSE
100

SUSE: 2020:3257-1 Moderate: Ceph and Deepsea Security Issue

An update that solves one vulnerability and has 35 fixes is now available. . SUSE Security Update: Security update for ceph, deepsea ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3257-1 Rating: moderate References: #1151612 #1152100 #1155045 #1155262 #1156087 #1156409 #1158257 #1159689 #1160626 #1161718 #1162553 #1163119 #1164571 #1165713 #1165835 #1165840 #1166297 #1166393 #1166624 #1166670 #1166932 #1167477 #1168403 #1169134 #1169356 #1170487 #1170938 #1171367 #1171921 #1171956 #1172142 #1173339 #1174591 #1175061 #1175240 #1175781 Cross-References: CVE-2020-10753 Affected Products: SUSE Enterprise Storage 6 ______________________________________________________________________________ An update that solves one vulnerability and has 35 fixes is now available. Description: This update for ceph, deepsea fixes the following issues: - Update to 14.2.13-398-gb6c514eec7: + Upstream 14.2.13 release see https://ceph.io/en/news/blog/2020/v14-2-13-nautilus-released/ * (bsc#1151612, bsc#1158257) ceph-volume: major batch refactor - Update to 14.2.12-436-g6feab505b7: + Upstream 14.2.12 release see https://ceph.io/en/news/blog/2020/v14-2-12-nautilus-released/ * (bsc#1169134) mgr/dashboard: document Prometheus' security model * (bsc#1170487) monclient: schedule first tick using mon_client_hunt_interval * (bsc#1174591) mgr/dashboard: Unable to edit iSCSI logged-in client * (bsc#1174591) mgr/dashboard: Allow editing iSCSI targets with initiators logged-in * (bsc#1175061) os/bluestore: dump onode that has too many spanning blobs * (bsc#1175240) pybind/mgr/restful: use dict.items() for py3 compatible + (bsc#1175781) ceph-volume: lvmcache: print helpcorrectly + spec: move python-enum34 into rhel 7 conditional - Update to 14.2.11-394-g9cbbc473c0: + Upstream 14.2.11 release see https://ceph.io/en/news/blog/2020/v14-2-11-nautilus-released/ * mgr/progress: Skip pg_summary update if _events dict is empty (bsc#1167477) (bsc#1172142) (bsc#1171956) * mgr/dashboard: Allow to edit iSCSI target with active session (bsc#1173339) - Update to 14.2.10-392-gb3a13b81cb: + Upstream 14.2.10 release see https://ceph.io/en/news/blog/2020/v14-2-10-nautilus-released/ * mgr: Improve internal python to c++ interface (bsc#1167477) - Update to 14.2.9-970-ged84cae0c9: + rgw: sanitize newlines in s3 CORSConfiguration's ExposeHeader (bsc#1171921, CVE-2020-10753) - Update to 14.2.9-969-g9917342dc8d: * rebase on top of upstream nautilus, SHA1 ccd9c04f88e53aef7e4f1068ce1221fa3b97450d * cmake: Improve test for 16-byte atomic support on IBM Z * (jsc#SES-680) monitoring: add details to Prometheus alerts * (bsc#1155045) mgr/dashboard: add debug mode, and accept expected exception when SSL handshaking * (bsc#1152100) monitoring: alert for prediction of disk and pool fill up broken * (bsc#1155262) mgr/dashboard: iSCSI targets not available if any gateway is down * (bsc#1159689) os/bluestore: more flexible DB volume space usage * (bsc#1156087) ceph-volume: make get_devices fs location independent * (bsc#1156409) monitoring: wait before firing osd full alert * (bsc#1160626) mgr/dashboard: Unable to remove an iSCSI gateway that is already in use * (bsc#1161718) mount.ceph: remove arbitrary limit on size of name option * (bsc#1162553) ceph-volume: strip _dmcrypt suffix in simple scan json output * (bsc#1163119) mgr/dashboard: Not able to restrict bucket creation for new user * (bsc#1164571) mgr/dashboard: Prevent iSCSI target recreation when editing controls *(bsc#1165713) mgr/dashboard: Repair broken grafana panels * (bsc#1165835) rgw: get barbican secret key request maybe return error code * (bsc#1165840) rgw: making implicit_tenants backwards compatible * (bsc#1166297) mgr/dashboard: Repair broken grafana panels * (bsc#1166393) mgr/dashboard: KeyError on dashboard reload * (bsc#1166624) mgr/dashboard: Fix iSCSI's username and password validation * (bsc#1166670) monitoring: root volume full alert fires false positives * (bsc#1166932) mgr: synchronize ClusterState's health and mon_status * (bsc#1168403) mgr/dashboard: Add more debug information to Dashboard RGW backend * (bsc#1169356) rgw: reshard: skip stale bucket id entries from reshard queue * (bsc#1170938) mon/OSDMonitor: allow trimming maps even if osds are down * (bsc#1171367) Set OSD's bluefs-buffered-io param to false by default - Update to 14.2.13-398-gb6c514eec7: + Upstream 14.2.13 release see https://ceph.io/en/news/blog/2020/v14-2-13-nautilus-released/ * (bsc#1151612, bsc#1158257) ceph-volume: major batch refactor - Update to 14.2.12-436-g6feab505b7: + Upstream 14.2.12 release see https://ceph.io/en/news/blog/2020/v14-2-12-nautilus-released/ * (bsc#1169134) mgr/dashboard: document Prometheus' security model * (bsc#1170487) monclient: schedule first tick using mon_client_hunt_interval * (bsc#1174591) mgr/dashboard: Unable to edit iSCSI logged-in client * (bsc#1174591) mgr/dashboard: Allow editing iSCSI targets with initiators logged-in * (bsc#1175061) os/bluestore: dump onode that has too many spanning blobs * (bsc#1175240) pybind/mgr/restful: use dict.items() for py3 compatible + (bsc#1175781) ceph-volume: lvmcache: print help correctly + spec: move python-enum34 into rhel 7 conditional - Update to 14.2.11-394-g9cbbc473c0: + Upstream 14.2.11 release see https://ceph.io/en/news/blog/2020/v14-2-11-nautilus-released/ * mgr/progress: Skip pg_summary update if _events dict is empty (bsc#1167477) (bsc#1172142) (bsc#1171956) * mgr/dashboard: Allow to edit iSCSI target with active session (bsc#1173339) - Update to 14.2.10-392-gb3a13b81cb: + Upstream 14.2.10 release see https://ceph.io/en/news/blog/2020/v14-2-10-nautilus-released/ * mgr: Improve internal python to c++ interface (bsc#1167477) - Update to 14.2.9-970-ged84cae0c9: + rgw: sanitize newlines in s3 CORSConfiguration's ExposeHeader (bsc#1171921, CVE-2020-10753) - Update to 14.2.9-969-g9917342dc8d: * rebase on top of upstream nautilus, SHA1 ccd9c04f88e53aef7e4f1068ce1221fa3b97450d * cmake: Improve test for 16-byte atomic support on IBM Z * (jsc#SES-680) monitoring: add details to Prometheus alerts * (bsc#1155045) mgr/dashboard: add debug mode, and accept expected exception when SSL handshaking * (bsc#1152100) monitoring: alert for prediction of disk and pool fill up broken * (bsc#1155262) mgr/dashboard: iSCSI targets not available if any gateway is down * (bsc#1159689) os/bluestore: more flexible DB volume space usage * (bsc#1156087) ceph-volume: make get_devices fs location independent * (bsc#1156409) monitoring: wait before firing osd full alert * (bsc#1160626) mgr/dashboard: Unable to remove an iSCSI gateway that is already in use * (bsc#1161718) mount.ceph: remove arbitrary limit on size of name option * (bsc#1162553) ceph-volume: strip _dmcrypt suffix in simple scan json output * (bsc#1163119) mgr/dashboard: Not able to restrict bucket creation for new user * (bsc#1164571) mgr/dashboard: Prevent iSCSI target recreation when editing controls * (bsc#1165713) mgr/dashboard: Repair broken grafana panels * (bsc#1165835) rgw: get barbican secret key request maybe return error code *(bsc#1165840) rgw: making implicit_tenants backwards compatible * (bsc#1166297) mgr/dashboard: Repair broken grafana panels * (bsc#1166393) mgr/dashboard: KeyError on dashboard reload * (bsc#1166624) mgr/dashboard: Fix iSCSI's username and password validation * (bsc#1166670) monitoring: root volume full alert fires false positives * (bsc#1166932) mgr: synchronize ClusterState's health and mon_status * (bsc#1168403) mgr/dashboard: Add more debug information to Dashboard RGW backend * (bsc#1169356) rgw: reshard: skip stale bucket id entries from reshard queue * (bsc#1170938) mon/OSDMonitor: allow trimming maps even if osds are down * (bsc#1171367) Set OSD's bluefs-buffered-io param to false by default - Version: 0.9.33 - drop workarounds for old ceph-volume lvm batch command - runners/upgrade: Add SES6-> 7 pre-upgrade checks Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2020-3257=1 Package List: - SUSE Enterprise Storage 6 (noarch): deepsea-0.9.33+git.0.ed16d26e-3.27.1 deepsea-cli-0.9.33+git.0.ed16d26e-3.27.1 References: https://www.suse.com/security/cve/CVE-2020-10753.html https://bugzilla.suse.com/1151612 https://bugzilla.suse.com/1152100 https://bugzilla.suse.com/1155045 https://bugzilla.suse.com/1155262 https://bugzilla.suse.com/1156087 https://bugzilla.suse.com/1156409 https://bugzilla.suse.com/1158257 https://bugzilla.suse.com/1159689 https://bugzilla.suse.com/1160626 https://bugzilla.suse.com/1161718 https://bugzilla.suse.com/1162553 https://bugzilla.suse.com/1163119 https://bugzilla.suse.com/1164571 https://bugzilla.suse.com/1165713 https://bugzilla.suse.com/1165835 https://bugzilla.suse.com/1165840 https://bugzilla.suse.com/1166297 https://bugzilla.suse.com/1166393 https://bugzilla.suse.com/1166624 https://bugzilla.suse.com/1166670 https://bugzilla.suse.com/1166932 https://bugzilla.suse.com/1167477 https://bugzilla.suse.com/1168403 https://bugzilla.suse.com/1169134 https://bugzilla.suse.com/1169356 https://bugzilla.suse.com/1170487 https://bugzilla.suse.com/1170938 https://bugzilla.suse.com/1171367 https://bugzilla.suse.com/1171921 https://bugzilla.suse.com/1171956 https://bugzilla.suse.com/1172142 https://bugzilla.suse.com/1173339 https://bugzilla.suse.com/1174591 https://bugzilla.suse.com/1175061 https://bugzilla.suse.com/1175240 https://bugzilla.suse.com/1175781 . SUSE releases address a notable vulnerability in ceph, deepsea, along with 35 supplementary patches aimed at improving overall system reliability.. SUSE Enterprise Storage, ceph security fix, deepsea update, moderate severity, ongoing maintenance. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2020 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here