MGASA-2026-0389

Source
https://advisories.mageia.org/MGASA-2026-0389.html
Import Source
https://advisories.mageia.org/MGASA-2026-0389.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0389
Upstream
Published
2026-09-09T23:52:21Z
Modified
2026-09-10T00:12:32Z
Summary
Updated ceph packages fix security vulnerabilities
Details

Updated ceph packages fix various security issues allowing authentication bypasses to gain admin privileges on the OSD, MDS, and MGR services. Notice that some of the fixes require kernel support for aes256k (introduced in kernel 7). This update will not break installs using the old (and insecure) AES keys; warnings will appear to migrate all keys (check out "ceph health detail" or "ceph status").

References
Credits

Affected packages

Mageia:10 / ceph

Package

Name
ceph
Purl
pkg:rpm/mageia/ceph?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.2.4-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0389.json"