[SRU] ceph 10.2.11

Bug #1784401 reported by James Page on 2018-07-30
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu Cloud Archive
Undecided
Unassigned
Mitaka
Medium
Unassigned
ceph (Ubuntu)
Undecided
Unassigned
Xenial
Medium
Unassigned

Bug Description

[Impact]
This release sports mostly bug-fixes and we would like to make sure all of our supported customers have access to these improvements.

The update contains the following package updates:

   * ceph 10.2.11

[Test Case]
The following SRU process was followed:

https://wiki.ubuntu.com/OpenStackUpdates

In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed. A successful run of all available tests will be required before the proposed packages can be let into -updates.

The OpenStack team will be in charge of attaching the output summary of the executed tests. The OpenStack team members will not mark ‘verification-done’ until this has happened.

[Regression Potential]
In order to mitigate the regression potential, the results of the
aforementioned tests are attached to this bug.

CVE References

James Page (james-page) on 2018-07-30
Changed in ceph (Ubuntu):
status: New → Invalid
Changed in cloud-archive:
status: New → Invalid
Changed in ceph (Ubuntu Xenial):
status: New → Triaged
importance: Undecided → Medium
description: updated
Alex Murray (alexmurray) wrote :

This would also happen to fix 3 outstanding CVEs for ceph in Xenial as well: CVE-2018-10861, CVE-2018-1128, CVE-2018-1129

I was looking at backporting fixes for these to 10.2.10 but the commits which fix the actual CVEs seem to depend on a fair few other commits in between 10.2.10 and 10.2.11 so if this SRU proceeds that will resolve these CVEs "for free"

James Page (james-page) wrote :

Uploaded to UNAPPROVED queue for SRU team review.

Hello James, or anyone else affected,

Accepted ceph into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/ceph/10.2.11-0ubuntu0.16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping!

N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.

Changed in ceph (Ubuntu Xenial):
status: Triaged → Fix Committed
tags: added: verification-needed verification-needed-xenial
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers