In the Linux kernel, the following vulnerability has been resolved:
ceph: fix memory leaks in cephmdscbuildpath()
Add putname() calls to error code paths that did not free the "path" pointer obtained by getname(). If ownership of this pointer is not passed to the caller via pathinfo.path, the function must free it before returning.
In the Linux kernel, the following vulnerability has been resolved:
ceph: supply snapshot context in cephzeropartialobject()
The cephzeropartialobject function was missing proper snapshot context for its OSD write operations, which could lead to data inconsistencies in snapshots.
Reproducer: ../src/vstart.sh --new -x --localhost --bluestore ./bin/ceph auth caps client.fsa mds 'allow rwps fsname=a' mon 'allow r fsname=a' osd 'allow rw tag cephfs data=a' mount -t ceph fsa@.a=/ /mnt/mycephfs/ -o conf=./ceph.conf dd if=/dev/urandom of=/mnt/mycephfs/foo bs=64K count=1 mkdir /mnt/mycephfs/.snap/snap1 md5sum /mnt/mycephfs/.snap/snap1/foo fallocate -p -o 0 -l 4096 /mnt/mycephfs/foo echo 3 > /proc/sys/vm/drop/caches md5sum /mnt/mycephfs/.snap/snap1/foo # get different md5sum!!