Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ceph | fixed | 18.2.8+ds-1 | package |
Примечания
https://www.openwall.com/lists/oss-security/2026/01/21/6
https://github.com/ceph/ceph/security/advisories/GHSA-xj9f-7g59-m4jx
https://github.com/ceph/ceph/pull/66142
Fixed by: https://github.com/ceph/ceph/commit/5081933c9a0068fe9deba4fca2d943bda3168518 (v18.2.8)
Связанные уязвимости
A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509 certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents
Уязвимость системы хранения данных Ceph, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании