Security update for ceph
This update for ceph fixes the following issues: - Update to version 12.2.7-420-gc0ef85b854: * https://ceph.com/releases/12-2-7-luminous-released/ * luminous: osd: eternal stuck PG in 'unfound_recovery' (bsc#1094932) * bluestore: db.slow used when db is not full (bsc#1092874) * CVE-2018-10861: Ensure that ceph-mon does perform authorization on all OSD pool ops (bsc#1099162). * CVE-2018-1129: cephx signature check bypass (bsc#1096748). * CVE-2018-1128: cephx protocol was vulnerable to replay attack (bsc#1096748).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ceph fixes the following issues: - Update to version 12.2.7-420-gc0ef85b854: * https://ceph.com/releases/12-2-7-luminous-released/ * luminous: osd: eternal stuck PG in 'unfound_recovery' (bsc#1094932) * bluestore: db.slow used when db is not full (bsc#1092874) * CVE-2018-10861: Ensure that ceph-mon does perform authorization on all OSD pool ops (bsc#1099162). * CVE-2018-1129: cephx signature check bypass (bsc#1096748). * CVE-2018-1128: cephx protocol was vulnerable to replay attack (bsc#1096748).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1092874
- https://bugzilla.suse.com/1094932
- https://bugzilla.suse.com/1096748
- https://bugzilla.suse.com/1099162
- https://www.suse.com/security/cve/CVE-2018-10861
- https://www.suse.com/security/cve/CVE-2018-1128
- https://www.suse.com/security/cve/CVE-2018-1129
- https://www.suse.com/support/update/announcement/2018/suse-su-20182193-1/