SUSE alert SUSE-SU-2023:1581-2 (ceph)
| From: | sle-security-updates@lists.suse.com | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2023:1581-2: important: Security update for ceph | |
| Date: | Tue, 02 May 2023 16:30:29 -0000 | |
| Message-ID: | <168304502918.19638.7882695902614117410@smelt2.suse.de> |
# Security update for ceph Announcement ID: SUSE-SU-2023:1581-2 Rating: important References: * #1187748 * #1188911 * #1192838 * #1192840 * #1196046 * #1199183 * #1200262 * #1200317 * #1200501 * #1200978 * #1201604 * #1201797 * #1201837 * #1201976 * #1202077 * #1202292 * #1203375 * #1204430 * #1205025 * #1205436 * #1206158 Cross-References: * CVE-2022-0670 * CVE-2022-3650 * CVE-2022-3854 CVSS scores: * CVE-2022-0670 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2022-0670 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-3650 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2022-3650 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-3854 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3854 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves three vulnerabilities and has 18 fixes can now be installed. ## Description: This update for ceph fixes the following issues: Security issues fixed: * CVE-2022-0670: Fixed user/tenant read/write access to an entire file system (bsc#1201837). * CVE-2022-3650: Fixed Python script that allowed privilege escalation from ceph to root (bsc#1204430). * CVE-2022-3854: Fixed possible DoS issue in ceph URL processing on RGW backends (bsc#1205025). Bug fixes: * osd, tools, kv: non-aggressive, on-line trimming of accumulated dups (bsc#1199183). * ceph-volume: fix fast device alloc size on mulitple device (bsc#1200262). * cephadm: update monitoring container images (bsc#1200501). * mgr/dashboard: prevent alert redirect (bsc#1200978). * mgr/volumes: Add subvolumegroup resize cmd (bsc#1201797). * monitoring/ceph-mixin: add RGW host to label info (bsc#1201976). * mgr/dashboard: enable addition of custom Prometheus alerts (bsc#1202077). * python-common: Add 'KB' to supported suffixes in SizeMatcher (bsc#1203375). * mgr/dashboard: fix rgw connect when using ssl (bsc#1205436). * ceph.spec.in: Add -DFMT_DEPRECATED_OSTREAM to CXXFLAGS (bsc#1202292). * cephfs-shell: move source to separate subdirectory (bsc#1201604). Fix in previous release: * mgr/cephadm: try to get FQDN for configuration files (bsc#1196046). * When an RBD is mapped, it is attempted to be deployed as an OSD. (bsc#1187748). * OSD marked down causes wrong backfill_toofull (bsc#1188911). * cephadm: Fix iscsi client caps (allow mgr <service status> calls) (bsc#1192838). * mgr/cephadm: fix and improve osd draining (bsc#1200317). * add iscsi and nfs to upgrade process (bsc#1206158). * mgr/mgr_module.py: CLICommand: Fix parsing of kwargs arguments (bsc#1192840). ## Patch Instructions: To install this SUSE Important update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-1581=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-1581=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * ceph-debugsource-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librbd1-debuginfo-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librados2-debuginfo-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librados2-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librbd1-16.2.11.58+g38d6afd3b78-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * ceph-debugsource-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librbd1-debuginfo-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librados2-debuginfo-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librados2-16.2.11.58+g38d6afd3b78-150400.3.6.1 * librbd1-16.2.11.58+g38d6afd3b78-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-0670.html * https://www.suse.com/security/cve/CVE-2022-3650.html * https://www.suse.com/security/cve/CVE-2022-3854.html * https://bugzilla.suse.com/show_bug.cgi?id=1187748 * https://bugzilla.suse.com/show_bug.cgi?id=1188911 * https://bugzilla.suse.com/show_bug.cgi?id=1192838 * https://bugzilla.suse.com/show_bug.cgi?id=1192840 * https://bugzilla.suse.com/show_bug.cgi?id=1196046 * https://bugzilla.suse.com/show_bug.cgi?id=1199183 * https://bugzilla.suse.com/show_bug.cgi?id=1200262 * https://bugzilla.suse.com/show_bug.cgi?id=1200317 * https://bugzilla.suse.com/show_bug.cgi?id=1200501 * https://bugzilla.suse.com/show_bug.cgi?id=1200978 * https://bugzilla.suse.com/show_bug.cgi?id=1201604 * https://bugzilla.suse.com/show_bug.cgi?id=1201797 * https://bugzilla.suse.com/show_bug.cgi?id=1201837 * https://bugzilla.suse.com/show_bug.cgi?id=1201976 * https://bugzilla.suse.com/show_bug.cgi?id=1202077 * https://bugzilla.suse.com/show_bug.cgi?id=1202292 * https://bugzilla.suse.com/show_bug.cgi?id=1203375 * https://bugzilla.suse.com/show_bug.cgi?id=1204430 * https://bugzilla.suse.com/show_bug.cgi?id=1205025 * https://bugzilla.suse.com/show_bug.cgi?id=1205436 * https://bugzilla.suse.com/show_bug.cgi?id=1206158