Bug#1144947: ceph: CVE-2025-30156 CVE-2026-39944 CVE-2026-50152 CVE-2026-54330

Daniel Baumann <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Hi,

updating ceph 18 (trixie) for the recent CVEs is a bit troublesome..

first, trixie currently has ceph 18.2.7, the latest 18.2.x is 18.2.8 so 
ideally I would like to update trixie to 18.2.8. The diff is rather 
large (huge even, if changes in the generated doc files are not filtered 
out), but it's very well tested and vetted by upstream, and also I can 
easily verify that with our production cluster as well before. For 
bookworm, we also did it similarly by even directly moving from 16.2.11 
to 16.2.15 via SRM. For trixie, can I do the CVE fixes based on 18.2.8 
or do you want me to backport all back to 18.2.7?

second, since ceph 18 is EOL and upstream will not provide an update for 
the recent CVEs, we need to cherry-pick and backport the patches from 
ceph 19 to ceph 18 ourselfs, but this isn't straight forward for now:

   * the actual fixes itself are spread over a bunch of commits (that's
     the easiest one :)

   * the fixes require the introduction of a entirely new CephX cryptokey
     type, which requires additional patches for the compatibility
     handling in "mixed" key situations and do add warnings/checks/etc
     for that in the cluster health handling. this will require
     exceptionally well and broad testing.

   * due to the above, following the 19.2.6 release (which we would take
     the CVE fixes from), upstream pushed additional corrections and
     adjustments (not passed their QR nor released yet), so, the work of
     getting the CVEs fixes "operationally proper" integrated for actual
     deployment is still ongoing.

so, in summary and fyi: regardless of 18.2.7 vs 18.2.8, this will likely 
take much more time to prepare the patches and test the patches, and I 
haven't looked at Ceph 16.x at all yet either. :(

Due to other planned events at work, I'm not able to start doing any of 
the above before Thursday next week.

Regards,
Daniel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.