Ceph: Urgent Security Update for Squid and Tentacle

The Ceph project has released two security-related hotfixes: Squid 19.2.6 and Tentacle 20.2.4. Operators of Ceph clusters should update immediately.

Generated by AI

The new Ceph versions address a total of four security vulnerabilities (CVEs) affecting, among other things, CephX authentication, the RADOS Gateway (RGW), and the Ceph Monitor. CVE-2025-30156 is particularly relevant: This vulnerability allows an authentication bypass and requires CephX keys to be rotated as part of the update. To address this, Ceph is introducing a new key type called aes256k.

For cephadm and Rook, parts of the key rotation are automated; however, special attention must be paid to client keys and existing OpenStack integrations. Additional upgrade steps apply to RGW multisite environments. Ceph strongly recommends upgrading existing installations to Squid 19.2.6 or Tentacle 20.2.4 as soon as possible.

With PVE 9.2 and Ceph 20.2.4, RBD operations may currently fail due to the removal of the --auth_supported option. An official bug report has since been filed regarding this issue.

You can find information about the security vulnerability here

Additional links to check out:

Tips from the Proxmox Forum

Official Bug Report

 

We're happy to assist you with upgrades and key rotation!

 

starline_logo_kontur_300
Enterprise Storage Solutions Team
Technik

Our experts are of course also experts in Linux, Ceph and ZFS