[Bug 2161000] Re: [SRU] Squid: Ceph new point release 19.2.6
Matthew Ruffell
2161000 at bugs.launchpad.net
Tue Sep 8 09:01:59 UTC 2026
Adding a comment from Dongdong Tao, which he raised elsewhere:
> Raising a dependency concern regarding release order: 19.2.6 (LP: #2161000)
> seems to be tracking ahead of 20.2.4 (no SRU bug filed yet).
>
> Not sure if the team plan to release 19.2.6 first, but releasing 19.2.6
> before 20.2.4 will introduce a critical upgrade regression window: 19.2.6
> contains the CVE fix and updated CephX key handling, whereas pre-20.2.4
> builds do not. Users upgrading from 19.2.6 to an unpatched 20.x release
> would hit authentication failures and break their clusters.
>
> Hence, I think 20.2.4 needs to be released before or alongside 19.2.6 to
> avoid this regression window.
Usual SRU policy is that all commits present in the -proposed upload, i.e.
everything in 19.2.6 also need to be present in resolute and stonking before it
can be released.
For this to happen, 20.2.4 must be released to both.
Adding block-proposed to this bug. Please get 20.2.4 into stonking and
resolute.
** Tags added: block-proposed block-proposed-noble
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to ceph in Ubuntu.
https://bugs.launchpad.net/bugs/2161000
Title:
[SRU] Squid: Ceph new point release 19.2.6
Status in ceph package in Ubuntu:
In Progress
Status in ceph source package in Noble:
Fix Committed
Bug description:
[Impact]
This release has both bug-fixes and security fixes. We are moving from 19.2.3 -> 19.2.6.
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-5-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-6-squid
19.2.6 resolved the following CVEs:
* CVE-2025-30156: AES-CBC misuse in CephX facilitating authentication bypass is an authentication bypass in CephX caused by misuse of AES-CBC.
* CVE-2026-39944: Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation shares the unauthenticated-encryption root cause of CVE-2025-30156, but applies it to RGW's STS session tokens resulting in improper verification of a cryptographic signature.
* CVE-2026-50152: Monitor config-key store readable by any CephX key is an improper authorization flaw in the Ceph Monitor subscription handler.
* CVE-2026-54330: SigV4 verifier error allows attachment of arbitrary x-amz-* headers resulting in privilege escalation is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.
The update contains the following package updates:
* d/p/pyo3-fix.patch: Refresh for 19.2.6 and sync cryptotools with upstream main.
* d/p/CVE-2024-31884.patch: Removed, fixed upstream.
* d/p/CVE-2024-47866.patch: Removed, fixed upstream.
* d/rules: Run dh_missing --list-missing.
* d/ceph-mgr-modules-core.install: Ship the rgw and mds_autoscaler mgr modules.
[Test Case]
The following SRU process was followed:
https://documentation.ubuntu.com/sru/en/latest/reference/exception-OpenStack-Updates
In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed. A successful run of all available tests will be required before the
proposed packages can be let into -updates.
The OpenStack team will be in charge of attaching the output summary
of the executed tests. The OpenStack team members will not mark
‘verification-done’ until this has happened.
[Regression Potential]
In order to mitigate the regression potential, the results of the aforementioned tests are attached to this bug.
[Other Information]
To SRU reviewers: We have already spoken to the security team, and decided together to process this backport first as a regular SRU, and later it will be rebuilt by security and published in the security pocket.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2161000/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list