• 公告ID (KylinSec-SA-2025-2481)

摘要:

ceph security update

安全等级: High

公告ID: KylinSec-SA-2025-2481

发布日期: 2025年5月11日

关联CVE: CVE-2024-48916  

  • 详细介绍

1. 漏洞描述

   

Ceph是一个高度可扩展的开源分布式存储系统,能够在通用硬件上运行,并提供对象存储、块存储和文件系统存储功能。

安全修复:

(CVE-2024-48916) Ceph Rados网关(RadosGW)的OIDC身份提供程序存在漏洞,攻击者可以通过提供算法(alg)为"none"的令牌来绕过JWT签名验证。这是由于实现中未能强制执行严格的签名验证,使得攻击者无需签名即可伪造有效令牌。

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-48916 V6 ceph Fixed

3. 影响组件

    ceph

4. 修复版本

   

V6

软件名称 架构 版本号
ceph-grafana-dashboards noarch 18.2.2-6.ks6.kb1
ceph-mgr-cephadm noarch 18.2.2-6.ks6.kb1
ceph-mgr-dashboard noarch 18.2.2-6.ks6.kb1
ceph-mgr-diskprediction-local noarch 18.2.2-6.ks6.kb1
ceph-mgr-k8sevents noarch 18.2.2-6.ks6.kb1
ceph-mgr-modules-core noarch 18.2.2-6.ks6.kb1
ceph-mgr-rook noarch 18.2.2-6.ks6.kb1
ceph-mib noarch 18.2.2-6.ks6.kb1
ceph-prometheus-alerts noarch 18.2.2-6.ks6.kb1
ceph-resource-agents noarch 18.2.2-6.ks6.kb1
ceph-volume noarch 18.2.2-6.ks6.kb1
cephadm noarch 18.2.2-6.ks6.kb1
cephfs-top noarch 18.2.2-6.ks6.kb1
ceph x86_64 18.2.2-6.ks6.kb1
ceph-base x86_64 18.2.2-6.ks6.kb1
ceph-common x86_64 18.2.2-6.ks6.kb1
ceph-exporter x86_64 18.2.2-6.ks6.kb1
ceph-fuse x86_64 18.2.2-6.ks6.kb1
ceph-immutable-object-cache x86_64 18.2.2-6.ks6.kb1
ceph-mds x86_64 18.2.2-6.ks6.kb1
ceph-mgr x86_64 18.2.2-6.ks6.kb1
ceph-mon x86_64 18.2.2-6.ks6.kb1
ceph-osd x86_64 18.2.2-6.ks6.kb1
ceph-radosgw x86_64 18.2.2-6.ks6.kb1
ceph-selinux x86_64 18.2.2-6.ks6.kb1
ceph-test x86_64 18.2.2-6.ks6.kb1
cephfs-mirror x86_64 18.2.2-6.ks6.kb1
libcephfs-devel x86_64 18.2.2-6.ks6.kb1
libcephfs2 x86_64 18.2.2-6.ks6.kb1
libcephsqlite x86_64 18.2.2-6.ks6.kb1
libcephsqlite-devel x86_64 18.2.2-6.ks6.kb1
librados-devel x86_64 18.2.2-6.ks6.kb1
librados2 x86_64 18.2.2-6.ks6.kb1
libradospp-devel x86_64 18.2.2-6.ks6.kb1
libradosstriper-devel x86_64 18.2.2-6.ks6.kb1
libradosstriper1 x86_64 18.2.2-6.ks6.kb1
librbd-devel x86_64 18.2.2-6.ks6.kb1
librbd1 x86_64 18.2.2-6.ks6.kb1
librgw-devel x86_64 18.2.2-6.ks6.kb1
librgw2 x86_64 18.2.2-6.ks6.kb1
python3-ceph-argparse x86_64 18.2.2-6.ks6.kb1
python3-ceph-common x86_64 18.2.2-6.ks6.kb1
python3-cephfs x86_64 18.2.2-6.ks6.kb1
python3-rados x86_64 18.2.2-6.ks6.kb1
python3-rbd x86_64 18.2.2-6.ks6.kb1
python3-rgw x86_64 18.2.2-6.ks6.kb1
rados-objclass-devel x86_64 18.2.2-6.ks6.kb1
rbd-fuse x86_64 18.2.2-6.ks6.kb1
rbd-mirror x86_64 18.2.2-6.ks6.kb1
rbd-nbd x86_64 18.2.2-6.ks6.kb1
ceph aarch64 18.2.2-6.ks6.kb1
ceph-base aarch64 18.2.2-6.ks6.kb1
ceph-common aarch64 18.2.2-6.ks6.kb1
ceph-exporter aarch64 18.2.2-6.ks6.kb1
ceph-fuse aarch64 18.2.2-6.ks6.kb1
ceph-immutable-object-cache aarch64 18.2.2-6.ks6.kb1
ceph-mds aarch64 18.2.2-6.ks6.kb1
ceph-mgr aarch64 18.2.2-6.ks6.kb1
ceph-mon aarch64 18.2.2-6.ks6.kb1
ceph-osd aarch64 18.2.2-6.ks6.kb1
ceph-radosgw aarch64 18.2.2-6.ks6.kb1
ceph-selinux aarch64 18.2.2-6.ks6.kb1
ceph-test aarch64 18.2.2-6.ks6.kb1
cephfs-mirror aarch64 18.2.2-6.ks6.kb1
libcephfs-devel aarch64 18.2.2-6.ks6.kb1
libcephfs2 aarch64 18.2.2-6.ks6.kb1
libcephsqlite aarch64 18.2.2-6.ks6.kb1
libcephsqlite-devel aarch64 18.2.2-6.ks6.kb1
librados-devel aarch64 18.2.2-6.ks6.kb1
librados2 aarch64 18.2.2-6.ks6.kb1
libradospp-devel aarch64 18.2.2-6.ks6.kb1
libradosstriper-devel aarch64 18.2.2-6.ks6.kb1
libradosstriper1 aarch64 18.2.2-6.ks6.kb1
librbd-devel aarch64 18.2.2-6.ks6.kb1
librbd1 aarch64 18.2.2-6.ks6.kb1
librgw-devel aarch64 18.2.2-6.ks6.kb1
librgw2 aarch64 18.2.2-6.ks6.kb1
python3-ceph-argparse aarch64 18.2.2-6.ks6.kb1
python3-ceph-common aarch64 18.2.2-6.ks6.kb1
python3-cephfs aarch64 18.2.2-6.ks6.kb1
python3-rados aarch64 18.2.2-6.ks6.kb1
python3-rbd aarch64 18.2.2-6.ks6.kb1
python3-rgw aarch64 18.2.2-6.ks6.kb1
rados-objclass-devel aarch64 18.2.2-6.ks6.kb1
rbd-fuse aarch64 18.2.2-6.ks6.kb1
rbd-mirror aarch64 18.2.2-6.ks6.kb1
rbd-nbd aarch64 18.2.2-6.ks6.kb1

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

V6:

x86_64:

     ceph-grafana-dashboards   

     ceph-mgr-cephadm   

     ceph-mgr-dashboard   

     ceph-mgr-diskprediction-local   

     ceph-mgr-k8sevents   

     ceph-mgr-modules-core   

     ceph-mgr-rook   

     ceph-mib   

     ceph-prometheus-alerts   

     ceph-resource-agents   

     ceph-volume   

     cephadm   

     cephfs-top   

     ceph   

     ceph-base   

     ceph-common   

     ceph-exporter   

     ceph-fuse   

     ceph-immutable-object-cache   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-selinux   

     ceph-test   

     cephfs-mirror   

     libcephfs-devel   

     libcephfs2   

     libcephsqlite   

     libcephsqlite-devel   

     librados-devel   

     librados2   

     libradospp-devel   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python3-ceph-argparse   

     python3-ceph-common   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

aarch64:

     ceph-grafana-dashboards   

     ceph-mgr-cephadm   

     ceph-mgr-dashboard   

     ceph-mgr-diskprediction-local   

     ceph-mgr-k8sevents   

     ceph-mgr-modules-core   

     ceph-mgr-rook   

     ceph-mib   

     ceph-prometheus-alerts   

     ceph-resource-agents   

     ceph-volume   

     cephadm   

     cephfs-top   

     ceph   

     ceph-base   

     ceph-common   

     ceph-exporter   

     ceph-fuse   

     ceph-immutable-object-cache   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-selinux   

     ceph-test   

     cephfs-mirror   

     libcephfs-devel   

     libcephfs2   

     libcephsqlite   

     libcephsqlite-devel   

     librados-devel   

     librados2   

     libradospp-devel   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python3-ceph-argparse   

     python3-ceph-common   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

上一篇:KylinSec-SA-2025-2477 下一篇:KylinSec-SA-2025-2377