Security update for ceph
This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357) - fsid mismatch when creating additional OSDs (bsc#1080788) - crash in civetweb/RGW (bsc#1081600)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357) - fsid mismatch when creating additional OSDs (bsc#1080788) - crash in civetweb/RGW (bsc#1081600)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1070357
- https://bugzilla.suse.com/1071386
- https://bugzilla.suse.com/1074301
- https://bugzilla.suse.com/1079076
- https://bugzilla.suse.com/1080788
- https://bugzilla.suse.com/1081379
- https://bugzilla.suse.com/1081600
- https://bugzilla.suse.com/1086340
- https://bugzilla.suse.com/1087269
- https://bugzilla.suse.com/1087493
- https://www.suse.com/security/cve/CVE-2018-7262
- https://www.suse.com/support/update/announcement/2018/suse-su-20181576-1/