Bug#1144947: ceph: CVE-2025-30156 CVE-2026-39944 CVE-2026-50152 CVE-2026-54330

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178724698829.3982340.10796229978513583242.reportbug__28352.8243935265$1787247077$gmane$org@eldamar.lan>
Source: ceph
Version: 20.2.2+ds-13
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for ceph, filling to be
on safe side as RC, maybe we can update to 20.2.4 to unstable
straight?

CVE-2025-30156[0], CVE-2026-39944[1], CVE-2026-50152[2],
CVE-2026-54330[3].

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-30156
    https://www.cve.org/CVERecord?id=CVE-2025-30156
[1] https://security-tracker.debian.org/tracker/CVE-2026-39944
    https://www.cve.org/CVERecord?id=CVE-2026-39944
[2] https://security-tracker.debian.org/tracker/CVE-2026-50152
    https://www.cve.org/CVERecord?id=CVE-2026-50152
[3] https://security-tracker.debian.org/tracker/CVE-2026-54330
    https://www.cve.org/CVERecord?id=CVE-2026-54330

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.