SUSE-SU-2018:1417-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20181417-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1417-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:1417-1
Related
Published
2018-06-07T13:10:58Z
Modified
2018-06-07T13:10:58Z
Summary
Security update for ceph
Details

This update for ceph fixes the following issues:

Security issues fixed:

  • CVE-2018-7262: rgw: malformed http headers can crash rgw (bsc#1081379).
  • CVE-2017-16818: User reachable asserts allow for DoS (bsc#1063014).

Bug fixes:

  • bsc#1061461: OSDs keep generating coredumps after adding new OSD node to cluster.
  • bsc#1079076: RGW openssl fixes.
  • bsc#1067088: Upgrade to SES5 restarted all nodes, majority of OSDs aborts during start.
  • bsc#1056125: Some OSDs are down when doing performance testing on rbd image in EC Pool.
  • bsc#1087269: allowecoverwrites option not in command options list.
  • bsc#1051598: Fix mountpoint check for systemctl enable --runtime.
  • bsc#1070357: Zabbix mgr module doesn't recover from HEALTH_ERR.
  • bsc#1066502: After upgrading a single OSD from SES 4 to SES 5 the OSDs do not rejoin the cluster.
  • bsc#1067119: Crushtool decompile creates wrong device entries (device 20 device20) for not existing / deleted OSDs.
  • bsc#1060904: Loglevel misleading during keystone authentication.
  • bsc#1056967: Monitors goes down after pool creation on cluster with 120 OSDs.
  • bsc#1067705: Issues with RGW Multi-Site Federation between SES5 and RH Ceph Storage 2.
  • bsc#1059458: Stopping / restarting rados gateway as part of deepsea stage.4 executions causes core-dump of radosgw.
  • bsc#1087493: Commvault cannot reconnect to storage after restarting haproxy.
  • bsc#1066182: Container synchronization between two Ceph clusters failed.
  • bsc#1081600: Crash in civetweb/RGW.
  • bsc#1054061: NFS-GANESHA service failing while trying to list mountpoint on client.
  • bsc#1074301: OSDs keep aborting: SnapMapper failed asserts.
  • bsc#1086340: XFS metadata corruption on rbd-nbd mapped image with journaling feature enabled.
  • bsc#1080788: fsid mismatch when creating additional OSDs.
  • bsc#1071386: Metadata spill onto block.slow.
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP3 / ceph

Package

Name
ceph
Purl
pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.2.5+git.1524775272.5e7ea8cf03-2.7.1

Ecosystem specific

{
    "binaries": [
        {
            "libcephfs2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librados2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rbd": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rgw": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rados": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librbd1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "ceph-common": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "libradosstriper1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-cephfs": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librgw2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP3 / ceph

Package

Name
ceph
Purl
pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.2.5+git.1524775272.5e7ea8cf03-2.7.1

Ecosystem specific

{
    "binaries": [
        {
            "libcephfs-devel": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librbd-devel": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librados-devel": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP3 / ceph

Package

Name
ceph
Purl
pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.2.5+git.1524775272.5e7ea8cf03-2.7.1

Ecosystem specific

{
    "binaries": [
        {
            "libcephfs2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librados2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rbd": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rgw": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rados": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librbd1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "ceph-common": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "libradosstriper1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-cephfs": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librgw2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP3 / ceph

Package

Name
ceph
Purl
pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.2.5+git.1524775272.5e7ea8cf03-2.7.1

Ecosystem specific

{
    "binaries": [
        {
            "libcephfs2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librados2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rbd": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rgw": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-rados": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librbd1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "ceph-common": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "libradosstriper1": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "python-cephfs": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1",
            "librgw2": "12.2.5+git.1524775272.5e7ea8cf03-2.7.1"
        }
    ]
}