{"schema_version":"1.7.3","id":"SUSE-SU-2020:3473-2","published":"2020-11-26T17:15:41Z","modified":"2026-02-04T03:27:03.985166Z","related":["CVE-2020-25660"],"upstream":["CVE-2020-25660"],"summary":"Security update for ceph","details":"This update for ceph fixes the following issues:\n\n- CVE-2020-25660: Bring back CEPHX_V2 authorizer challenges (bsc#1177843).\n- Added --container-init feature (bsc#1177319, bsc#1163764)\n- Made journald as the logdriver again (bsc#1177933)\n- Fixes a condition check for copy_tree, copy_files, and move_files in cephadm (bsc#1177676)\n- Fixed a bug where device_health_metrics pool gets created even without any OSDs in the cluster (bsc#1173079)\n- Log cephadm output /var/log/ceph/cephadm.log (bsc#1174644)\n- Fixed a bug where the orchestrator didn't come up anymore after the deletion of OSDs (bsc#1176499)\n- Fixed a bug where cephadm fails to deploy all OSDs and gets stuck (bsc#1177450)\n- python-common will no longer skip unavailable disks (bsc#1177151)\n- Added snap-schedule module (jsc#SES-704)\n- Updated the SES7 downstream branding (bsc#1175120, bsc#1175161, bsc#1175169, bsc#1170498)\n","affected":[{"package":{"name":"ceph","ecosystem":"SUSE:Enterprise Storage 7","purl":"pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.2.5.667+g1a579d5bf2-3.5.1"}]}],"ecosystem_specific":{"binaries":[{"ceph-base":"15.2.5.667+g1a579d5bf2-3.5.1","ceph-common":"15.2.5.667+g1a579d5bf2-3.5.1","cephadm":"15.2.5.667+g1a579d5bf2-3.5.1","libcephfs2":"15.2.5.667+g1a579d5bf2-3.5.1","librados2":"15.2.5.667+g1a579d5bf2-3.5.1","librbd1":"15.2.5.667+g1a579d5bf2-3.5.1","librgw2":"15.2.5.667+g1a579d5bf2-3.5.1","python3-ceph-argparse":"15.2.5.667+g1a579d5bf2-3.5.1","python3-ceph-common":"15.2.5.667+g1a579d5bf2-3.5.1","python3-cephfs":"15.2.5.667+g1a579d5bf2-3.5.1","python3-rados":"15.2.5.667+g1a579d5bf2-3.5.1","python3-rbd":"15.2.5.667+g1a579d5bf2-3.5.1","python3-rgw":"15.2.5.667+g1a579d5bf2-3.5.1","rbd-nbd":"15.2.5.667+g1a579d5bf2-3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3473-2.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20203473-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1163764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170498"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173079"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174466"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176451"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176499"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177078"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177151"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177450"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177643"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177676"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177843"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178073"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178531"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25660"}]}