ceph (14.2.21-1) unstable; urgency=high
authorThomas Goirand <zigo@debian.org>
Thu, 27 May 2021 10:04:21 +0000 (11:04 +0100)
committerThomas Goirand <zigo@debian.org>
Thu, 27 May 2021 10:04:21 +0000 (11:04 +0100)
commitb511396ba97ac33d9ac1e0e65f0f53e520bee40c
tree8dcea61978a49ab242f5cc56e5e74d50fce2a4e9
parent4ae192f1988785335cfdd1293b532f5dc5c6d8b2
parent5da0eae5ce2d4742341211e7bacbd8d2bda9ae6e
ceph (14.2.21-1) unstable; urgency=high

  * New upstream release, resolving these:
    - CVE-2021-3509: Cross Site Scripting via token Cookie (Closes: #988888).
    - CVE-2021-3524: injection of HTTP headers via a CORS ExposeHeader tag in
      the Ceph Storage RadosGW (Closes: #988889).
    - CVE-2021-3531: RadosGW denial of service (crash) (Closes: #988890).

[dgit import unpatched ceph 14.2.21-1]
100 files changed:
debian/.gitlab-ci.yml
debian/README.Debian
debian/calc-max-parallel.sh
debian/ceph-base.ceph.init
debian/ceph-base.dirs
debian/ceph-base.docs
debian/ceph-base.install
debian/ceph-base.postinst
debian/ceph-base.postrm
debian/ceph-common.install
debian/ceph-common.lintian-overrides
debian/ceph-common.manpages
debian/ceph-common.postinst
debian/ceph-common.postrm
debian/ceph-common.preinst
debian/ceph-common.rbdmap.init
debian/ceph-fs-common.install
debian/ceph-fuse.lintian-overrides
debian/ceph-fuse.manpages
debian/ceph-mds.lintian-overrides
debian/ceph-mds.postinst
debian/ceph-mgr-k8sevents.install
debian/ceph-mgr-k8sevents.postinst
debian/ceph-mgr.install
debian/ceph-mon.postinst
debian/ceph-osd.install
debian/ceph.NEWS
debian/ceph.lintian-overrides
debian/changelog
debian/clean
debian/compat
debian/control
debian/copyright
debian/gbp.conf
debian/lib-systemd/system-sleep/ceph
debian/lib-systemd/system/ceph-create-keys.service
debian/lib-systemd/system/ceph-mds.service
debian/lib-systemd/system/ceph-mon.service
debian/lib-systemd/system/ceph-osd@.service
debian/libcephfs-dev.install
debian/libcephfs-jni.install
debian/libcephfs-jni.lintian-overrides
debian/libcephfs2.install
debian/libcephfs2.lintian-overrides
debian/libcephfs2.symbols
debian/librados-dev.install
debian/librados2.install
debian/librados2.lintian-overrides
debian/librados2.symbols
debian/libradosstriper-dev.install
debian/libradosstriper1.install
debian/libradosstriper1.symbols
debian/librbd-dev.install
debian/librbd1.install
debian/librbd1.symbols
debian/librgw-dev.install
debian/librgw2.install
debian/man/ceph-crush-location.1
debian/man/mount.fuse.ceph.8
debian/missing-sources/bootstrap.js
debian/missing-sources/two.js
debian/patches/32bit-avoid-overloading.patch
debian/patches/32bit-avoid-size_t.patch
debian/patches/add-option-to-disable-ceph-dencoder.patch
debian/patches/allow-bgp-to-host.patch
debian/patches/another-cmakelists-fix.patch
debian/patches/bluefs-use-uint64_t-for-len.patch
debian/patches/civetweb-755-1.8-somaxconn-configurable.patch
debian/patches/civetweb-755-1.8-somaxconn-configurable_conf.patch
debian/patches/civetweb-755-1.8-somaxconn-configurable_test.patch
debian/patches/cmake_add_1.74_to_known_versions.patch
debian/patches/cmake_define_BOOST_ASIO_USE_TS_EXECUTOR_AS_DEFAULT_for_Boost.Asio_users.patch
debian/patches/debian-armel-armhf-buildflags.patch
debian/patches/disable-crypto.patch
debian/patches/fix-bash-completion-location
debian/patches/fix-ceph-osd-systemd-target.patch
debian/patches/make-ceph-python-3.9-aware.patch
debian/patches/mds-purgequeue-use_uint64_t.patch
debian/patches/riscv64-link-pthread.patch
debian/patches/series
debian/patches/update-java-source-target-flags.patch
debian/python3-ceph.lintian-overrides
debian/radosgw.install
debian/radosgw.lintian-overrides
debian/radosgw.postinst
debian/radosgw.prerm
debian/rest-bench.install
debian/rules
debian/source.lintian-overrides
debian/source/format
debian/source/lintian-overrides
debian/source/options
debian/tests/build-rados
debian/tests/build-rbd
debian/tests/ceph-client
debian/tests/control
debian/tests/python-ceph
debian/udev/95-ceph-osd-lvm.rules
debian/watch
debian/workarounds/ceph-dencoder-oom