[Bug 2161000] Re: [SRU] Squid: Ceph new point release 19.2.6
John Ramsden
2161000 at bugs.launchpad.net
Wed Sep 9 23:59:03 UTC 2026
Just a quick update for anyone tracking this. We are working through
some issues around the release related to how we communicate the change
and some other implications to the cve change (kernel), as well as how
it affects some other projects. We are also coordinating with getting
the 20.2.4 SRU released around a similar time -
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2166817
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to ceph in Ubuntu.
https://bugs.launchpad.net/bugs/2161000
Title:
[SRU] Squid: Ceph new point release 19.2.6
Status in ceph package in Ubuntu:
In Progress
Status in ceph source package in Noble:
Fix Committed
Bug description:
[Impact]
This release has both bug-fixes and security fixes. We are moving from 19.2.3 -> 19.2.6.
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-4-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-5-squid
* https://docs.ceph.com/en/latest/releases/squid/#v19-2-6-squid
19.2.6 resolved the following CVEs:
* CVE-2025-30156: AES-CBC misuse in CephX facilitating authentication bypass is an authentication bypass in CephX caused by misuse of AES-CBC.
* CVE-2026-39944: Ceph RGW STS tokens vulnerable to CBC bit-flip privilege escalation shares the unauthenticated-encryption root cause of CVE-2025-30156, but applies it to RGW's STS session tokens resulting in improper verification of a cryptographic signature.
* CVE-2026-50152: Monitor config-key store readable by any CephX key is an improper authorization flaw in the Ceph Monitor subscription handler.
* CVE-2026-54330: SigV4 verifier error allows attachment of arbitrary x-amz-* headers resulting in privilege escalation is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.
The update contains the following package updates:
* d/p/pyo3-fix.patch: Refresh for 19.2.6 and sync cryptotools with upstream main.
* d/p/CVE-2024-31884.patch: Removed, fixed upstream.
* d/p/CVE-2024-47866.patch: Removed, fixed upstream.
* d/rules: Run dh_missing --list-missing.
* d/ceph-mgr-modules-core.install: Ship the rgw and mds_autoscaler mgr modules.
[Test Case]
The following SRU process was followed:
https://documentation.ubuntu.com/sru/en/latest/reference/exception-OpenStack-Updates
In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed. A successful run of all available tests will be required before the
proposed packages can be let into -updates.
The OpenStack team will be in charge of attaching the output summary
of the executed tests. The OpenStack team members will not mark
‘verification-done’ until this has happened.
[Regression Potential]
In order to mitigate the regression potential, the results of the aforementioned tests are attached to this bug.
[Other Information]
To SRU reviewers: We have already spoken to the security team, and decided together to process this backport first as a regular SRU, and later it will be rebuilt by security and published in the security pocket.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/2161000/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list