This update for ceph version 13.2.4 fixes the following issues:
Security issues fixed:
- CVE-2018-14662: Fixed an issue with LUKS 'config-key' safety (bsc#1111177)
- CVE-2018-10861: Fixed an authorization bypass on OSD pool ops in ceph-mon (bsc#1099162)
- CVE-2018-1128: Fixed signature check bypass in cephx (bsc#1096748)
- CVE-2018-1129: Fixed replay attack in cephx protocol (bsc#1096748)
- CVE-2018-16846: Enforced bounds on max-keys/max-uploads/max-parts in rgw (bsc#1114710)
Non-security issues fixed:
- ceph-volume Python 3 fixes (bsc#1114567)
- Fixed python3 module loading (bsc#1086613)
- Fixed an issue where ceph build fails (bsc#1084645)
- ceph's SPDK builds with march=native (bsc#1101262)
This update was imported from the SUSE:SLE-15:Update update project.
-
Submitted by
Nathan Cutler (smithfarm)