{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0389",
  "published": "2026-09-09T23:52:21Z",
  "modified": "2026-09-09T22:47:53Z",
  "summary": "Updated ceph packages fix security vulnerabilities",
  "details": "Updated ceph packages fix various security issues allowing\nauthentication bypasses to gain admin privileges on the OSD, MDS, and\nMGR services. Notice that some of the fixes require kernel support for\naes256k (introduced in kernel 7). This update will not break installs\nusing the old (and insecure) AES keys; warnings will appear to migrate\nall keys (check out \"ceph health detail\" or \"ceph status\").\n",
  "upstream": [
    "CVE-2025-30156",
    "CVE-2026-50152",
    "CVE-2026-54330",
    "CVE-2026-39944"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0389.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36147"
    },
    {
      "type": "WEB",
      "url": "https://docs.ceph.com/en/latest/rados/configuration/auth-config-ref/index.html#upgrading-and-rotating-cephx-keys"
    },
    {
      "type": "WEB",
      "url": "https://www.openwall.com/lists/oss-security/2026/08/19/4"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj"
    },
    {
      "type": "ADVISORY",
      "url": "https://docs.ceph.com/en/latest/security/CVE-2025-30156/"
    },
    {
      "type": "WEB",
      "url": "https://web.mit.edu/tlyu/papers/krb4peril-ndss04.pdf"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h"
    },
    {
      "type": "ADVISORY",
      "url": "https://docs.ceph.com/en/latest/security/CVE-2026-50152/"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj"
    },
    {
      "type": "ADVISORY",
      "url": "https://docs.ceph.com/en/latest/security/CVE-2026-54330"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2"
    },
    {
      "type": "ADVISORY",
      "url": "https://docs.ceph.com/en/latest/security/CVE-2026-39944"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "ceph",
        "purl": "pkg:rpm/mageia/ceph?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "20.2.4-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
