[Bug 2161000] Re: [SRU] Squid: Ceph new point release 19.2.6

Renan Rodrigo 2161000 at bugs.launchpad.net
Tue Sep 8 13:08:07 UTC 2026


Thanks for looking, Matthew!
Yes, this is expected: we had no intention to mark this as verification-done before the upload to R+S happens.
There is ongoing work to bring the new 20.2.x version to the newer releases.

-- 
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to ceph in Ubuntu.
https://bugs.launchpad.net/bugs/2161000

Title:
  [SRU] Squid: Ceph new point release 19.2.6

Status in ceph package in Ubuntu:
  In Progress
Status in ceph source package in Noble:
  Fix Committed

Bug description:
  [Impact]
  This release has both bug-fixes and security fixes. We are moving from 19.2.3 -> 19.2.6.

  * https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid
  * https://docs.ceph.com/en/latest/releases/squid/#v19-2-5-squid
  * https://docs.ceph.com/en/latest/releases/squid/#v19-2-6-squid

  19.2.6 resolved the following CVEs:

  * CVE-2025-30156: AES-CBC misuse in CephX facilitating authentication bypass is an authentication bypass in CephX caused by misuse of AES-CBC.
  * CVE-2026-39944: Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation shares the unauthenticated-encryption root cause of CVE-2025-30156, but applies it to RGW's STS session tokens resulting in improper verification of a cryptographic signature.
  * CVE-2026-50152: Monitor config-key store readable by any CephX key is an improper authorization flaw in the Ceph Monitor subscription handler.
  * CVE-2026-54330: SigV4 verifier error allows attachment of arbitrary x-amz-* headers resulting in privilege escalation is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.

  The update contains the following package updates:

     * d/p/pyo3-fix.patch: Refresh for 19.2.6 and sync cryptotools with upstream main.
     * d/p/CVE-2024-31884.patch: Removed, fixed upstream.
     * d/p/CVE-2024-47866.patch: Removed, fixed upstream.
     * d/rules: Run dh_missing --list-missing.
     * d/ceph-mgr-modules-core.install: Ship the rgw and mds_autoscaler mgr modules.

  [Test Case]
  The following SRU process was followed:
  https://documentation.ubuntu.com/sru/en/latest/reference/exception-OpenStack-Updates

  In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed.  A successful run of all available tests will be required before the
  proposed packages can be let into -updates.

  The OpenStack team will be in charge of attaching the output summary
  of the executed tests. The OpenStack team members will not mark
  ‘verification-done’ until this has happened.

  [Regression Potential]
  In order to mitigate the regression potential, the results of the aforementioned tests are attached to this bug.

  [Other Information]
  To SRU reviewers: We have already spoken to the security team, and decided together to process this backport first as a regular SRU, and later it will be rebuilt by security and published in the security pocket.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2161000/+subscriptions




More information about the Ubuntu-openstack-bugs mailing list