{"affected":[{"ecosystem_specific":{"binaries":[{"ceph-common":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libcephfs2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librados2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libradosstriper1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librbd1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librgw2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-cephfs":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rados":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rbd":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rgw":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"ceph","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libcephfs-devel":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librados-devel":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librbd-devel":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP3","name":"ceph","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ceph-common":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libcephfs2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librados2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libradosstriper1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librbd1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librgw2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-cephfs":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rados":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rbd":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rgw":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"ceph","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ceph-common":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libcephfs2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librados2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","libradosstriper1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librbd1":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","librgw2":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-cephfs":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rados":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rbd":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1","python-rgw":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"ceph","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"12.2.5+git.1524775272.5e7ea8cf03-2.7.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for ceph fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-7262: rgw: malformed http headers can crash rgw (bsc#1081379).\n- CVE-2017-16818: User reachable asserts allow for DoS (bsc#1063014).\n\nBug fixes:\n\n- bsc#1061461: OSDs keep generating coredumps after adding new OSD node to cluster.\n- bsc#1079076: RGW openssl fixes.\n- bsc#1067088: Upgrade to SES5 restarted all nodes, majority of OSDs aborts during start.\n- bsc#1056125: Some OSDs are down when doing performance testing on rbd image in EC Pool.\n- bsc#1087269: allow_ec_overwrites option not in command options list.\n- bsc#1051598: Fix mountpoint check for systemctl enable --runtime.\n- bsc#1070357: Zabbix mgr module doesn't recover from HEALTH_ERR.\n- bsc#1066502: After upgrading a single OSD from SES 4 to SES 5 the OSDs do not rejoin the cluster.\n- bsc#1067119: Crushtool decompile creates wrong device entries (device 20 device20) for not existing / deleted OSDs.\n- bsc#1060904: Loglevel misleading during keystone authentication.\n- bsc#1056967: Monitors goes down after pool creation on cluster with 120 OSDs.\n- bsc#1067705: Issues with RGW Multi-Site Federation between SES5 and RH Ceph Storage 2.\n- bsc#1059458: Stopping / restarting rados gateway as part of deepsea stage.4 executions causes core-dump of radosgw.\n- bsc#1087493: Commvault cannot reconnect to storage after restarting haproxy.\n- bsc#1066182: Container synchronization between two Ceph clusters failed.\n- bsc#1081600: Crash in civetweb/RGW.\n- bsc#1054061: NFS-GANESHA service failing while trying to list mountpoint on client.\n- bsc#1074301: OSDs keep aborting: SnapMapper failed asserts.\n- bsc#1086340: XFS metadata corruption on rbd-nbd mapped image with journaling feature enabled.\n- bsc#1080788: fsid mismatch when creating additional OSDs.\n- bsc#1071386: Metadata spill onto block.slow.\n","id":"SUSE-SU-2018:1417-1","modified":"2018-06-07T13:10:58Z","published":"2018-06-07T13:10:58Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20181417-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1051598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1054061"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056125"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1059458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1060904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1061461"},{"type":"REPORT","url":"https://bugzilla.suse.com/1063014"},{"type":"REPORT","url":"https://bugzilla.suse.com/1066182"},{"type":"REPORT","url":"https://bugzilla.suse.com/1066502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1067088"},{"type":"REPORT","url":"https://bugzilla.suse.com/1067119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1067705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1070357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071386"},{"type":"REPORT","url":"https://bugzilla.suse.com/1074301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1079076"},{"type":"REPORT","url":"https://bugzilla.suse.com/1080788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1081379"},{"type":"REPORT","url":"https://bugzilla.suse.com/1081600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1087269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1087493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-7262"}],"related":["CVE-2017-16818","CVE-2018-7262"],"summary":"Security update for ceph","upstream":["CVE-2017-16818","CVE-2018-7262"]}