MGASA-2022-0138

Source
https://advisories.mageia.org/MGASA-2022-0138.html
Import Source
https://advisories.mageia.org/MGASA-2022-0138.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0138
Related
Published
2022-04-13T16:06:19Z
Modified
2022-04-13T15:21:50Z
Summary
Updated ceph packages fix security vulnerability
Details

Updated ceph packages fix security vulnerabilities: the key length for encrypted devices created using ceph-volume is incorrect. This is due to a bug in ceph_volume/util/encryption.py which is fixed by this new version. (CVE-2021-3979)

References
Credits

Affected packages

Mageia:8 / ceph

Package

Name
ceph
Purl
pkg:rpm/mageia/ceph?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.2.16-1.mga8

Ecosystem specific

{
    "section": "core"
}