[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:1581-1 -- SLES ceph, librgw-devel, libcephfs2, python3-ceph-argparse, rados-objclass-devel, librgw2, librados2, librados-devel, python3-cephfs, libradospp-devel, rbd-nbd, python3-ceph-common, librbd1, python3-rbd, python3-rgw, librbd-devel, libcephfs-devel, python3-rados

ID: oval:org.secpod.oval:def:89048658Date: (C)2023-04-25   (M)2023-12-26
Class: PATCHFamily: unix




This update for ceph fixes the following issues: Security issues fixed: * CVE-2022-0670: Fixed user/tenant read/write access to an entire file system . * CVE-2022-3650: Fixed Python script that allowed privilege escalation from ceph to root . * CVE-2022-3854: Fixed possible DoS issue in ceph URL processing on RGW backends . Bug fixes: * osd, tools, kv: non-aggressive, on-line trimming of accumulated dups . * ceph-volume: fix fast device alloc size on mulitple device . * cephadm: update monitoring container images . * mgr/dashboard: prevent alert redirect . * mgr/volumes: Add subvolumegroup resize cmd . * monitoring/ceph-mixin: add RGW host to label info . * mgr/dashboard: enable addition of custom Prometheus alerts . * python-common: Add "KB" to supported suffixes in SizeMatcher . * mgr/dashboard: fix rgw connect when using ssl . * ceph.spec.in: Add -DFMT_DEPRECATED_OSTREAM to CXXFLAGS . * cephfs-shell: move source to separate subdirectory . Fix in previous release: * mgr/cephadm: try to get FQDN for configuration files . * When an RBD is mapped, it is attempted to be deployed as an OSD. * OSD marked down causes wrong backfill_toofull . * cephadm: Fix iscsi client caps . * mgr/cephadm: fix and improve osd draining . * add iscsi and nfs to upgrade process . * mgr/mgr_module.py: CLICommand: Fix parsing of kwargs arguments .

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP4
Product:
ceph
librgw-devel
libcephfs2
python3-ceph-argparse
rados-objclass-devel
librgw2
librados2
librados-devel
python3-cephfs
libradospp-devel
rbd-nbd
python3-ceph-common
librbd1
python3-rbd
python3-rgw
librbd-devel
libcephfs-devel
python3-rados
Reference:
SUSE-SU-2023:1581-1
CVE-2022-0670
CVE-2022-3650
CVE-2022-3854
CVE    3
CVE-2022-0670
CVE-2022-3650
CVE-2022-3854
CPE    20
cpe:/a:python:python3-rados
cpe:/a:librgw:librgw-devel
cpe:/a:rados-objclass:rados-objclass-devel
cpe:/a:librbd:librbd-devel
...

© SecPod Technologies