RHSA-2025:22548HighCVSS 8.8

Red Hat Security Advisory: Red Hat Ceph Storage

Published
December 2, 2025
Last Modified
August 18, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-56433 — shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-11230 — haproxy: denial of service vulnerability in HAProxy mjson library CVE-2025-11561 — sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems

🎯 Affected products13

  • Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/grafana-rhel9@sha256:1d1953d6ed948441a2d441b5050b6bc4f3b8ac66e1724bb0eb2fae2cb56267d3_arm64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/grafana-rhel9@sha256:97950d588d5b033ab672114c0f5cd96ebd39246795511e7fe2fd1277aa94a1c8_s390x as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/grafana-rhel9@sha256:9ddb4ab1d3b584f33d6ae2756b13f74e50b5a55630b3000df963595b36ef1b61_amd64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/grafana-rhel9@sha256:b5f1c693c7a01a39ac46a2a35d61f786d3f79deb62fe55e7fdac1ba627fb6dc9_ppc64le as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:04a48d31f7336e0d5958eed1ddb1a117148f791baccef4e6e08943181e6794c8_amd64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:08f8552a0a56a47ab606bed47b603e3d2aedaa389d4a5df4dbfa06acee85c0c0_ppc64le as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1_arm64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:75e6643866fa05fce50284a164d48533259c91be3fcac85556844a67e25887e9_s390x as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:2fbfd8ab9adf2a0ee77b5ef5c07be5787a6820ef40b5eef3a27628d94bf188a6_amd64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:75d9ee1d25f4770172b0243aab13a13895f1be84fa0695efdad4a33428594843_ppc64le as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:aea85ef95ff6a40839955c80a64dad0c4ff8bcfd1f4b0b15262caee21ee26ef3_arm64 as a component of Red Hat Ceph Storage 8
  • registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:eef8a3d296b098659dfdfb64a9e89b9f955015e29d69976eb3f9feffc9304a34_s390x as a component of Red Hat Ceph Storage 8

✅ Remediation

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, ensure the SSSD Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is configured and the an2ln plugin is disabled by adding "disable = an2ln" in a krb5 include file, for example /var/lib/sss/pubconf/krb5.include.d/localauth_plugin and make sure it is included in the Kerberos configuration. Apply vendor updates and follow Red Hat guidance for SSSD hardening.

🔗 References (9)