• 公告ID (KylinSec-SA-2024-4147)

摘要:

ceph security update

安全等级: Medium

公告ID: KylinSec-SA-2024-4147

发布日期: 2024年11月8日

关联CVE: CVE-2023-46159  

  • 详细介绍

1. 漏洞描述

   

Ceph是一个可大规模扩展的开源分布式存储系统,它运行在商用硬件上,并提供对象、块和文件系统的存储。

安全修复:

IBM Storage Ceph 5.3z1、5.3z5和6.1z1版本可能允许网络上的已认证用户通过RGW(Rados Gateway)造成拒绝服务攻击。IBM X-Force ID:268906。(CVE-2023-46159)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-46159 KY3.4-5A ceph Fixed

3. 影响组件

    ceph

4. 修复版本

   

KY3.4-5A

软件名称 架构 版本号
ceph x86_64 12.2.8-25.kb1.ky3_4
ceph-base x86_64 12.2.8-25.kb1.ky3_4
ceph-common x86_64 12.2.8-25.kb1.ky3_4
ceph-fuse x86_64 12.2.8-25.kb1.ky3_4
ceph-mds x86_64 12.2.8-25.kb1.ky3_4
ceph-mgr x86_64 12.2.8-25.kb1.ky3_4
ceph-mon x86_64 12.2.8-25.kb1.ky3_4
ceph-osd x86_64 12.2.8-25.kb1.ky3_4
ceph-radosgw x86_64 12.2.8-25.kb1.ky3_4
ceph-resource-agents x86_64 12.2.8-25.kb1.ky3_4
ceph-selinux x86_64 12.2.8-25.kb1.ky3_4
ceph-test x86_64 12.2.8-25.kb1.ky3_4
libcephfs-devel x86_64 12.2.8-25.kb1.ky3_4
libcephfs2 x86_64 12.2.8-25.kb1.ky3_4
librados-devel x86_64 12.2.8-25.kb1.ky3_4
librados2 x86_64 12.2.8-25.kb1.ky3_4
libradosstriper-devel x86_64 12.2.8-25.kb1.ky3_4
libradosstriper1 x86_64 12.2.8-25.kb1.ky3_4
librbd-devel x86_64 12.2.8-25.kb1.ky3_4
librbd1 x86_64 12.2.8-25.kb1.ky3_4
librgw-devel x86_64 12.2.8-25.kb1.ky3_4
librgw2 x86_64 12.2.8-25.kb1.ky3_4
python-ceph-compat x86_64 12.2.8-25.kb1.ky3_4
python-cephfs x86_64 12.2.8-25.kb1.ky3_4
python-rados x86_64 12.2.8-25.kb1.ky3_4
python-rbd x86_64 12.2.8-25.kb1.ky3_4
python-rgw x86_64 12.2.8-25.kb1.ky3_4
python3-ceph-argparse x86_64 12.2.8-25.kb1.ky3_4
python3-cephfs x86_64 12.2.8-25.kb1.ky3_4
python3-rados x86_64 12.2.8-25.kb1.ky3_4
python3-rbd x86_64 12.2.8-25.kb1.ky3_4
python3-rgw x86_64 12.2.8-25.kb1.ky3_4
rados-objclass-devel x86_64 12.2.8-25.kb1.ky3_4
rbd-fuse x86_64 12.2.8-25.kb1.ky3_4
rbd-mirror x86_64 12.2.8-25.kb1.ky3_4
rbd-nbd x86_64 12.2.8-25.kb1.ky3_4
ceph aarch64 12.2.8-25.kb1.ky3_4
ceph-base aarch64 12.2.8-25.kb1.ky3_4
ceph-common aarch64 12.2.8-25.kb1.ky3_4
ceph-fuse aarch64 12.2.8-25.kb1.ky3_4
ceph-mds aarch64 12.2.8-25.kb1.ky3_4
ceph-mgr aarch64 12.2.8-25.kb1.ky3_4
ceph-mon aarch64 12.2.8-25.kb1.ky3_4
ceph-osd aarch64 12.2.8-25.kb1.ky3_4
ceph-radosgw aarch64 12.2.8-25.kb1.ky3_4
ceph-resource-agents aarch64 12.2.8-25.kb1.ky3_4
ceph-selinux aarch64 12.2.8-25.kb1.ky3_4
ceph-test aarch64 12.2.8-25.kb1.ky3_4
libcephfs-devel aarch64 12.2.8-25.kb1.ky3_4
libcephfs2 aarch64 12.2.8-25.kb1.ky3_4
librados-devel aarch64 12.2.8-25.kb1.ky3_4
librados2 aarch64 12.2.8-25.kb1.ky3_4
libradosstriper-devel aarch64 12.2.8-25.kb1.ky3_4
libradosstriper1 aarch64 12.2.8-25.kb1.ky3_4
librbd-devel aarch64 12.2.8-25.kb1.ky3_4
librbd1 aarch64 12.2.8-25.kb1.ky3_4
librgw-devel aarch64 12.2.8-25.kb1.ky3_4
librgw2 aarch64 12.2.8-25.kb1.ky3_4
python-ceph-compat aarch64 12.2.8-25.kb1.ky3_4
python-cephfs aarch64 12.2.8-25.kb1.ky3_4
python-rados aarch64 12.2.8-25.kb1.ky3_4
python-rbd aarch64 12.2.8-25.kb1.ky3_4
python-rgw aarch64 12.2.8-25.kb1.ky3_4
python3-ceph-argparse aarch64 12.2.8-25.kb1.ky3_4
python3-cephfs aarch64 12.2.8-25.kb1.ky3_4
python3-rados aarch64 12.2.8-25.kb1.ky3_4
python3-rbd aarch64 12.2.8-25.kb1.ky3_4
python3-rgw aarch64 12.2.8-25.kb1.ky3_4
rados-objclass-devel aarch64 12.2.8-25.kb1.ky3_4
rbd-fuse aarch64 12.2.8-25.kb1.ky3_4
rbd-mirror aarch64 12.2.8-25.kb1.ky3_4
rbd-nbd aarch64 12.2.8-25.kb1.ky3_4

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.4-5A:

x86_64:

     ceph   

     ceph-base   

     ceph-common   

     ceph-fuse   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-resource-agents   

     ceph-selinux   

     ceph-test   

     libcephfs-devel   

     libcephfs2   

     librados-devel   

     librados2   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python-ceph-compat   

     python-cephfs   

     python-rados   

     python-rbd   

     python-rgw   

     python3-ceph-argparse   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

aarch64:

     ceph   

     ceph-base   

     ceph-common   

     ceph-fuse   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-resource-agents   

     ceph-selinux   

     ceph-test   

     libcephfs-devel   

     libcephfs2   

     librados-devel   

     librados2   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python-ceph-compat   

     python-cephfs   

     python-rados   

     python-rbd   

     python-rgw   

     python3-ceph-argparse   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

上一篇:KylinSec-SA-2024-4146 下一篇:KylinSec-SA-2024-4190