19.2.6-1
Clyso Enterprise Storage 19.2.6-1 is a curated Ceph release based on upstream
Ceph v19.2.6 (Squid).
| Release information | Value |
|---|---|
| CES release | 19.2.6-1 |
| Upstream base | Ceph v19.2.6 (Squid) |
| Released | October 6, 2026 |
| Container image | harbor.clyso.com/ces/ceph/ceph:ces-v19.2.6-1 |
| cephadm | Download URL pending release validation; contact CLYSO Support |
The container tag is the intended CES 19 release artifact. The container image is public and no registry login is needed.
Default settings
CES 19.2.6-1 includes the following CLYSO-curated Squid defaults:
| Setting | Default |
|---|---|
mds_cache_trim_threshold | 512_K |
osd_max_pg_per_osd_hard_ratio | 10 |
osd_op_queue | wpq |
rgw_thread_pool_size | 128 |
Bug fixes
RGW S3 SigV4 x-amz-content-sha256 signing
Backports Ceph PR #69003.
CVE-2026-54330 SigV4 hardening introduced a regression by not signing the
x-amz-content-sha256 header. This backport ensures that the header is always
included in AWS Signature Version 4 signatures.
ceph-volume and cephadm WAL/DB OSD deployment
Includes Ceph PR #68752, which fixes ceph-volume and cephadm deployment of OSDs with separate WAL and DB devices.
Upgrade compatibility fix
Includes Ceph PR #60063. This avoids
upgrade failures when moving between releases that differ in whether the
corresponding manager patch is present. Specifically MGR fixes to pools with inf coming from the read balancer.
cephadm OSD restarting because reconfig operation
Fixes the Squid behavior where every cephadm reconfig of an OSD stops and restarts that OSD. Ceph tracker issue #80440.
Additional cephadm fixes
Includes fixes associated with Ceph tracker issue #74775.
Dashboard
- Added CLYSO branding to the Ceph Dashboard.
Included CES functionality
- CLYSO manager module for metrics, diagnostics, health checks, and recovery tooling
Installation and upgrades
- For a new cluster, follow Install CES.
- For an existing cephadm-managed cluster, follow the upgrade and migration guide.
Known issues
The upstream Ceph 19.2.6 release has known issues documented on the Ceph Squid known-bugs page. CES 19.2.6-1 includes a downstream fix for the OSD reconfiguration restart behavior described above. Review the full known-bugs page for other issues before deploying or upgrading.
Security fixes
CES 19.2.6-1 contains fixes for the following Ceph security vulnerabilities. Review the linked advisories to determine their relevance to your deployment.
| Advisory | Affected area | Summary |
|---|---|---|
| CVE-2025-30156 | CephX | Corrects AES-CBC misuse that could facilitate an authentication bypass. |
| CVE-2026-39944 | RGW STS | Prevents CBC bit-flip privilege escalation involving STS tokens. |
| CVE-2026-50152 | Monitor | Restricts unauthorized access to the monitor config-key store through CephX keys. |
| CVE-2026-54330 | RGW S3 API | Corrects SigV4 verification of x-amz-* headers that could allow privilege escalation. |
The additional x-amz-content-sha256 signing correction described under
Bug fixes addresses a regression
introduced by the CVE-2026-54330 hardening.
Support
Contact CLYSO Support for more information if needed.