QID 174976

QID 174976: SUSE Enterprise Linux Security Update for ceph (SUSE-SU-2021:1474-1)

This update for ceph fixes the following issues:

- ceph was updated to 15.2.11-83-g8a15f484c2:
* CVE-2021-20288: Fixed unauthorized global_id reuse (bsc#1183074).
* disk gets replaced with no rocksdb/wal (bsc#1184231).
* BlueStore handles huge(>4GB) writes from RocksDB to BlueFS poorly,
potentially causing data corruption (bsc#1183899).

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:1474-1 to address this issue and obtain further details.

    CVEs related to QID 174976

    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:1474-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-May/008722.html