MGASA-2026-0389
Dashboard / Vulnerabilities / MGASA-2026-0389
MGASA-2026-0389
Summary: Updated ceph packages fix security vulnerabilities
Details: Updated ceph packages fix various security issues allowing authentication bypasses to gain admin privileges on the OSD, MDS, and MGR services. Notice that some of the fixes require kernel support for aes256k (introduced in kernel 7). This update will not break installs using the old (and insecure) AES keys; warnings will appear to migrate all keys (check out "ceph health detail" or "ceph status").
References: https://advisories.mageia.org/MGASA-2026-0389.html, https://bugs.mageia.org/show_bug.cgi?id=36147, https://docs.ceph.com/en/latest/rados/configuration/auth-config-ref/index.html#upgrading-and-rotating-cephx-keys, https://www.openwall.com/lists/oss-security/2026/08/19/4, https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj, https://docs.ceph.com/en/latest/security/CVE-2025-30156/, https://web.mit.edu/tlyu/papers/krb4peril-ndss04.pdf, https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h, https://docs.ceph.com/en/latest/security/CVE-2026-50152/, https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj, https://docs.ceph.com/en/latest/security/CVE-2026-54330, https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2, https://docs.ceph.com/en/latest/security/CVE-2026-39944
Affected packages
Package
Name: ceph
Purl: pkg:rpm/mageia/ceph?arch=source&distro=mageia-10
Affected ranges
Type: ECOSYSTEM
Events:
