SUSE-SU-2018:1576-1

    Dashboard / Vulnerabilities / SUSE-SU-2018:1576-1

    SUSE-SU-2018:1576-1

    Published: 7 Jun 2018Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for ceph

    Details: This update for ceph to 12.2.5-407-g5e7ea8cf03 fixes the following issues: Security issue fixed: - CVE-2018-7262: The rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. rgw: make init env methods return an error (bsc#1081379) Other issues fixed: - osd: do not crash on empty snapset (bsc#1074301) - mon: add 'ceph osd pool get erasure allow_ec_overwrites' command (bsc#1087269) - journal: limit number of appends sent in one librados op (bsc#1086340) - RGW user stats fixes (bsc#1087493) - rgw openssl fixes (bsc#1079076, bsc#1081379) - rocksdb: fixes early metadata spill over to slow device in bluefs (bsc#1071386) - mon: reenable timer to send digest when paxos is temporarily inactive (bsc#1070357) - fsid mismatch when creating additional OSDs (bsc#1080788) - crash in civetweb/RGW (bsc#1081600)

    Affected packages

    Package

    Name: ceph

    Purl: pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%205

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -12.2.5+git.1524775272.5e7ea8cf03-2.13.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High