Re: [CVE] [URGENT] Squid v19.2.6 and Tentacle v20.2.4 released
On Thu, Aug 20, 2026 at 4:33 AM Iztok Gregori <ceph-users@ceph.io> wrote:
Silly question maybe, but I want to be sure, for RBD clients (Proxmox QEMU virtual machines in my case) the new key type needs updated "client libraries" to be "understood", right?
If you're using the rbd kernel driver, the kernel must be updated. If you also rely on userspace libraries or mount helpers, those need updated too. The main focus should be on upgrading the Ceph service daemons and rotating keys. Once that's complete, the main vulnerability can be considered closed. Upgrading client keys is still encouraged where possible. -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D
On 20/08/26 15:32, Patrick Donnelly wrote:
On Thu, Aug 20, 2026 at 4:33 AM Iztok Gregori <ceph-users@ceph.io> wrote:
Silly question maybe, but I want to be sure, for RBD clients (Proxmox QEMU virtual machines in my case) the new key type needs updated "client libraries" to be "understood", right?
If you're using the rbd kernel driver, the kernel must be updated. If you also rely on userspace libraries or mount helpers, those need updated too.
I suspected that, thank you for confirmation.
The main focus should be on upgrading the Ceph service daemons and rotating keys. Once that's complete, the main vulnerability can be considered closed. Upgrading client keys is still encouraged where possible.
Ok, noted. Thank you! Iztok
participants (2)
-
Iztok Gregori
-
Patrick Donnelly