• 公告ID (KylinSec-SA-2025-2592)

摘要:

ceph security update

安全等级: High

公告ID: KylinSec-SA-2025-2592

发布日期: 2025年8月18日

关联CVE: CVE-2024-48916  

  • 详细介绍

1. 漏洞描述

   

Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage.

Security Fix(es):

A vulnerability in the Ceph Rados Gateway (RadosGW) OIDC provider allows attackers to bypass JWT signature verification by supplying a token with "none" as the algorithm (alg). This occurs because the implementation fails to enforce strict signature validation, enabling attackers to forge valid tokens without a signature.(CVE-2024-48916)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-48916 KY3.5.3 ceph Fixed

3. 影响组件

    ceph

4. 修复版本

   

KY3.5.3

软件名称 架构 版本号
ceph-grafana-dashboards noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-cephadm noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-dashboard noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-diskprediction-local noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-k8sevents noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-modules-core noarch 16.2.7-22.ky3_5.kb1
ceph-mgr-rook noarch 16.2.7-22.ky3_5.kb1
ceph-prometheus-alerts noarch 16.2.7-22.ky3_5.kb1
cephadm noarch 16.2.7-22.ky3_5.kb1
cephfs-top noarch 16.2.7-22.ky3_5.kb1
ceph x86_64 16.2.7-22.ky3_5.kb1
ceph-base x86_64 16.2.7-22.ky3_5.kb1
ceph-common x86_64 16.2.7-22.ky3_5.kb1
ceph-fuse x86_64 16.2.7-22.ky3_5.kb1
ceph-immutable-object-cache x86_64 16.2.7-22.ky3_5.kb1
ceph-mds x86_64 16.2.7-22.ky3_5.kb1
ceph-mgr x86_64 16.2.7-22.ky3_5.kb1
ceph-mon x86_64 16.2.7-22.ky3_5.kb1
ceph-osd x86_64 16.2.7-22.ky3_5.kb1
ceph-radosgw x86_64 16.2.7-22.ky3_5.kb1
ceph-resource-agents x86_64 16.2.7-22.ky3_5.kb1
ceph-selinux x86_64 16.2.7-22.ky3_5.kb1
ceph-test x86_64 16.2.7-22.ky3_5.kb1
cephfs-mirror x86_64 16.2.7-22.ky3_5.kb1
libcephfs-devel x86_64 16.2.7-22.ky3_5.kb1
libcephfs2 x86_64 16.2.7-22.ky3_5.kb1
libcephsqlite x86_64 16.2.7-22.ky3_5.kb1
libcephsqlite-devel x86_64 16.2.7-22.ky3_5.kb1
librados-devel x86_64 16.2.7-22.ky3_5.kb1
librados2 x86_64 16.2.7-22.ky3_5.kb1
libradospp-devel x86_64 16.2.7-22.ky3_5.kb1
libradosstriper-devel x86_64 16.2.7-22.ky3_5.kb1
libradosstriper1 x86_64 16.2.7-22.ky3_5.kb1
librbd-devel x86_64 16.2.7-22.ky3_5.kb1
librbd1 x86_64 16.2.7-22.ky3_5.kb1
librgw-devel x86_64 16.2.7-22.ky3_5.kb1
librgw2 x86_64 16.2.7-22.ky3_5.kb1
python3-ceph-argparse x86_64 16.2.7-22.ky3_5.kb1
python3-ceph-common x86_64 16.2.7-22.ky3_5.kb1
python3-cephfs x86_64 16.2.7-22.ky3_5.kb1
python3-rados x86_64 16.2.7-22.ky3_5.kb1
python3-rbd x86_64 16.2.7-22.ky3_5.kb1
python3-rgw x86_64 16.2.7-22.ky3_5.kb1
rados-objclass-devel x86_64 16.2.7-22.ky3_5.kb1
rbd-fuse x86_64 16.2.7-22.ky3_5.kb1
rbd-mirror x86_64 16.2.7-22.ky3_5.kb1
rbd-nbd x86_64 16.2.7-22.ky3_5.kb1
ceph aarch64 16.2.7-22.ky3_5.kb1
ceph-base aarch64 16.2.7-22.ky3_5.kb1
ceph-common aarch64 16.2.7-22.ky3_5.kb1
ceph-fuse aarch64 16.2.7-22.ky3_5.kb1
ceph-immutable-object-cache aarch64 16.2.7-22.ky3_5.kb1
ceph-mds aarch64 16.2.7-22.ky3_5.kb1
ceph-mgr aarch64 16.2.7-22.ky3_5.kb1
ceph-mon aarch64 16.2.7-22.ky3_5.kb1
ceph-osd aarch64 16.2.7-22.ky3_5.kb1
ceph-radosgw aarch64 16.2.7-22.ky3_5.kb1
ceph-resource-agents aarch64 16.2.7-22.ky3_5.kb1
ceph-selinux aarch64 16.2.7-22.ky3_5.kb1
ceph-test aarch64 16.2.7-22.ky3_5.kb1
cephfs-mirror aarch64 16.2.7-22.ky3_5.kb1
libcephfs-devel aarch64 16.2.7-22.ky3_5.kb1
libcephfs2 aarch64 16.2.7-22.ky3_5.kb1
libcephsqlite aarch64 16.2.7-22.ky3_5.kb1
libcephsqlite-devel aarch64 16.2.7-22.ky3_5.kb1
librados-devel aarch64 16.2.7-22.ky3_5.kb1
librados2 aarch64 16.2.7-22.ky3_5.kb1
libradospp-devel aarch64 16.2.7-22.ky3_5.kb1
libradosstriper-devel aarch64 16.2.7-22.ky3_5.kb1
libradosstriper1 aarch64 16.2.7-22.ky3_5.kb1
librbd-devel aarch64 16.2.7-22.ky3_5.kb1
librbd1 aarch64 16.2.7-22.ky3_5.kb1
librgw-devel aarch64 16.2.7-22.ky3_5.kb1
librgw2 aarch64 16.2.7-22.ky3_5.kb1
python3-ceph-argparse aarch64 16.2.7-22.ky3_5.kb1
python3-ceph-common aarch64 16.2.7-22.ky3_5.kb1
python3-cephfs aarch64 16.2.7-22.ky3_5.kb1
python3-rados aarch64 16.2.7-22.ky3_5.kb1
python3-rbd aarch64 16.2.7-22.ky3_5.kb1
python3-rgw aarch64 16.2.7-22.ky3_5.kb1
rados-objclass-devel aarch64 16.2.7-22.ky3_5.kb1
rbd-fuse aarch64 16.2.7-22.ky3_5.kb1
rbd-mirror aarch64 16.2.7-22.ky3_5.kb1
rbd-nbd aarch64 16.2.7-22.ky3_5.kb1

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.5.3:

x86_64:

     ceph-grafana-dashboards   

     ceph-mgr-cephadm   

     ceph-mgr-dashboard   

     ceph-mgr-diskprediction-local   

     ceph-mgr-k8sevents   

     ceph-mgr-modules-core   

     ceph-mgr-rook   

     ceph-prometheus-alerts   

     cephadm   

     cephfs-top   

     ceph   

     ceph-base   

     ceph-common   

     ceph-fuse   

     ceph-immutable-object-cache   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-resource-agents   

     ceph-selinux   

     ceph-test   

     cephfs-mirror   

     libcephfs-devel   

     libcephfs2   

     libcephsqlite   

     libcephsqlite-devel   

     librados-devel   

     librados2   

     libradospp-devel   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python3-ceph-argparse   

     python3-ceph-common   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

aarch64:

     ceph-grafana-dashboards   

     ceph-mgr-cephadm   

     ceph-mgr-dashboard   

     ceph-mgr-diskprediction-local   

     ceph-mgr-k8sevents   

     ceph-mgr-modules-core   

     ceph-mgr-rook   

     ceph-prometheus-alerts   

     cephadm   

     cephfs-top   

     ceph   

     ceph-base   

     ceph-common   

     ceph-fuse   

     ceph-immutable-object-cache   

     ceph-mds   

     ceph-mgr   

     ceph-mon   

     ceph-osd   

     ceph-radosgw   

     ceph-resource-agents   

     ceph-selinux   

     ceph-test   

     cephfs-mirror   

     libcephfs-devel   

     libcephfs2   

     libcephsqlite   

     libcephsqlite-devel   

     librados-devel   

     librados2   

     libradospp-devel   

     libradosstriper-devel   

     libradosstriper1   

     librbd-devel   

     librbd1   

     librgw-devel   

     librgw2   

     python3-ceph-argparse   

     python3-ceph-common   

     python3-cephfs   

     python3-rados   

     python3-rbd   

     python3-rgw   

     rados-objclass-devel   

     rbd-fuse   

     rbd-mirror   

     rbd-nbd   

上一篇:KylinSec-SA-2025-1258 下一篇:KylinSec-SA-2025-2741