First published: Thu Jun 15 2023(Updated: )
Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services.<br>These new packages include numerous enhancements and bug fixes. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Ceph Storage Release Notes for information on the<br>most significant of these changes:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6.1/html/release_notes/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6.1/html/release_notes/index</a> Security Fix(es):<br><li> moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)</li> <li> angular: XSS vulnerability (CVE-2021-4231)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>All users of Red Hat Ceph Storage are advised to update to these packages that provide numerous enhancements and bug fixes.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-collection-ansible-posix | <1.2.0-1.3.el9 | 1.2.0-1.3.el9 |
redhat/ceph | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/cephadm-ansible | <2.15.0-1.el9c | 2.15.0-1.el9c |
redhat/ceph-base | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-base-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-common | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-common-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-debugsource | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-exporter-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-fuse | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-fuse-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-immutable-object-cache | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-immutable-object-cache-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-mds-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-mgr-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-mib | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-mon-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-osd-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-radosgw-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-resource-agents | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-selinux | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/ceph-test-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/cephadm | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/cephfs-mirror-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/cephfs-top | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libcephfs-devel | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libcephfs2 | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libcephfs2-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libcephsqlite-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librados-devel | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librados-devel-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librados2 | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librados2-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libradospp-devel | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libradosstriper1 | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/libradosstriper1-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librbd-devel | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librbd1 | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librbd1-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librgw-devel | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librgw2 | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/librgw2-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-ceph-argparse | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-ceph-common | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-cephfs | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-cephfs-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rados | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rados-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rbd | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rbd-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rgw | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/python3-rgw-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/rbd-fuse-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/rbd-mirror-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/rbd-nbd | <17.2.6-70.el9c | 17.2.6-70.el9c |
redhat/rbd-nbd-debuginfo | <17.2.6-70.el9c | 17.2.6-70.el9c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2023:3623 is classified with moderate severity due to various enhancements and bug fixes in the Red Hat Ceph Storage software.
To fix RHSA-2023:3623, update the affected packages to the versions specified in the advisory.
Affected packages include, but are not limited to, ansible-collection-ansible-posix, ceph, ceph-common, and python3-ceph-common.
RHSA-2023:3623 includes numerous enhancements and bug fixes that improve the stability and performance of Red Hat Ceph Storage.
Yes, several bugs have been documented in Bugzilla related to RHSA-2023:3623, which may affect users if not addressed promptly.