SUSE: 2019:2736-1 moderate: ceph, ceph-iscsi, ses-manual_en
Summary
This update for ceph, ceph-iscsi and ses-manual_en fixes the following issues: Security issues fixed: - CVE-2019-10222: Fixed RGW crash caused by unauthenticated clients. (bsc#1145093) Non-security issues-fixed: - ceph-volume: prints errors to stdout with --format json (bsc#1132767) - mgr/dashboard: Changing rgw-api-host does not get effective without disable/enable dashboard mgr module (bsc#1137503) - mgr/dashboard: Silence Alertmanager alerts (bsc#1141174) - mgr/dashboard: Fix e2e failures caused by webdriver version (bsc#1145759) - librbd: always try to acquire exclusive lock when removing image (bsc#1149093) - The no{up,down,in,out} related commands have been revamped (bsc#1151990) - radosgw-admin gets two new subcommands for managing expire-stale objects. (bsc#1151991) - Deploying a single new BlueStore OSD on a cluster upgraded to SES6 from SES5 breaks pool utilization stats reported by ceph df (bsc#1151992) ...
Read the Full AdvisoryReferences
#1132767 #1134444 #1135584 #1137503 #1140491
#1141174 #1145093 #1145617 #1145618 #1145759
#1146656 #1147132 #1149093 #1150406 #1151439
#1151990 #1151991 #1151992 #1151993 #1151994
#1151995 #1152002
Cross- CVE-2019-10222
Affected Products:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
SUSE Linux Enterprise Module for Basesystem 15-SP1
SUSE Enterprise Storage 6
https://www.suse.com/security/cve/CVE-2019-10222.html
https://bugzilla.suse.com/1132767
https://bugzilla.suse.com/1134444
https://bugzilla.suse.com/1135584
https://bugzilla.suse.com/1137503
https://bugzilla.suse.com/1140491
https://bugzilla.suse.com/1141174
https://bugzilla.suse.com/1145093
https://bugzilla.suse.com/1145617
https://bugzilla.suse.com/1145618
https://bugzilla.suse.com/1145759
https://bugzilla.suse.com/1146656
http...
Read the Full Advisory