I have subscribed ubuntu-security to this bug, as it contains security
updates / CVE fixes.
To SRU reviewers: We have already spoken to the security team, and
decided together to process this backport first as a regular SRU, and
later it will be rebuilt by security and published in the security
pocket.
** Also affects: ceph (Ubuntu Noble)
Importance: Undecided
Status: New
** Changed in: ceph (Ubuntu Noble)
Status: New => In Progress
** Changed in: ceph (Ubuntu Noble)
Assignee: (unassigned) => John Ramsden (johnramsden)
** Description changed:
[Impact]
This release has both bug-fixes and security fixes. We are moving from 19.2.3
-> 19.2.6.
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-5-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-6-squid
19.2.6 resolved the following CVEs:
* CVE-2025-30156: AES-CBC misuse in CephX facilitating authentication bypass
is an authentication bypass in CephX caused by misuse of AES-CBC.
* CVE-2026-39944: Ceph RGW STS tokens vulnerable to CBC bit-flip privilege
escalation shares the unauthenticated-encryption root cause of CVE-2025-30156,
but applies it to RGW's STS session tokens resulting in improper verification
of a cryptographic signature.
* CVE-2026-50152: Monitor config-key store readable by any CephX key is an
improper authorization flaw in the Ceph Monitor subscription handler.
* CVE-2026-54330: SigV4 verifier error allows attachment of arbitrary x-amz-*
headers resulting in privilege escalation is a flaw in RGW not properly
verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.
The update contains the following package updates:
* d/p/pyo3-fix.patch: Refresh for 19.2.6.
* d/p/pyo3-fix.patch: Sync cryptotools with upstream main.
* d/p/CVE-2024-31884.patch: Removed, fixed upstream.
* d/p/CVE-2024-47866.patch: Removed, fixed upstream.
* d/rules: Run dh_missing --list-missing.
* d/ceph-mgr-modules-core.install: Ship the rgw and mds_autoscaler mgr
modules.
[Test Case]
The following SRU process was followed:
https://documentation.ubuntu.com/sru/en/latest/reference/exception-OpenStack-Updates
In order to avoid regression of existing consumers, the OpenStack team will
run their continuous integration test against the packages that are in
-proposed. A successful run of all available tests will be required before the
proposed packages can be let into -updates.
The OpenStack team will be in charge of attaching the output summary of
the executed tests. The OpenStack team members will not mark
‘verification-done’ until this has happened.
[Regression Potential]
In order to mitigate the regression potential, the results of the
aforementioned tests are attached to this bug.
+
+ [Other Information]
+ To SRU reviewers: We have already spoken to the security team, and decided
together to process this backport first as a regular SRU, and later it will be
rebuilt by security and published in the security pocket.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161000
Title:
[SRU] Squid: Ceph new point release 19.2.6
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2161000/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs