Comment 1 for bug 1940959

Revision history for this message
Ponnuvel Palaniyappan (pponnuvel) wrote (last edit ):

The primary aim is to have a Nautilus release for fixing the
CVE 2021-20288 [0].

The fix for [0] went into 14.2.20. Since 142.22 has already been
released (upstream) and likely to be last point release in Nautlius,
it makes sense to target that.

[0] https://docs.ceph.com/en/latest/security/CVE-2021-20288/#cve-2021-20288-unauthorized-global-id-reuse-in-cephx