** Description changed: [Impact] - This release sports mostly bug-fixes and we would like to make sure all of our users have access to these improvements. + This release has both bug-fixes and security fixes. We are moving from 19.2.3 -> 19.2.6. + + * https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid + * https://docs.ceph.com/en/latest/releases/squid/#v19-2-5-squid + * https://docs.ceph.com/en/latest/releases/squid/#v19-2-6-squid + + 19.2.6 resolved the following CVEs: + + * CVE-2025-30156: AES-CBC misuse in CephX facilitating authentication bypass is an authentication bypass in CephX caused by misuse of AES-CBC. + * CVE-2026-39944: Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation shares the unauthenticated-encryption root cause of CVE-2025-30156, but applies it to RGW's STS session tokens resulting in improper verification of a cryptographic signature. + * CVE-2026-50152: Monitor config-key store readable by any CephX key is an improper authorization flaw in the Ceph Monitor subscription handler. + * CVE-2026-54330: SigV4 verifier error allows attachment of arbitrary x-amz-* headers resulting in privilege escalation is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier. The update contains the following package updates: - https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid - - This is simply a minor version bump and there were no packaging changes - required + * d/p/pyo3-fix.patch: Refresh for 19.2.6. + * d/p/pyo3-fix.patch: Sync cryptotools with upstream main. + * d/p/CVE-2024-31884.patch: Removed, fixed upstream. + * d/p/CVE-2024-47866.patch: Removed, fixed upstream. + * d/rules: Run dh_missing --list-missing. + * d/ceph-mgr-modules-core.install: Ship the rgw and mds_autoscaler mgr modules. [Test Case] The following SRU process was followed: https://documentation.ubuntu.com/sru/en/latest/reference/exception-OpenStack-Updates In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed. A successful run of all available tests will be required before the proposed packages can be let into -updates. The OpenStack team will be in charge of attaching the output summary of the executed tests. The OpenStack team members will not mark ‘verification-done’ until this has happened. [Regression Potential] In order to mitigate the regression potential, the results of the aforementioned tests are attached to this bug.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2161000 Title: [SRU] Squid: Ceph new point release 19.2.6 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2161000/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
