RHSA-2026:1536MediumCVSS 7.5

Red Hat Security Advisory: Red Hat Ceph Storage 9.0 Security and Enhancement update

Published
January 29, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-25153 — containerd: OCI image importer memory exhaustion CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-31884 — pybind: Improper use of Pybind CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2025-52555 — ceph: privilege escalation by unprivileged users in a ceph-fuse mounted CephFS

🎯 Affected products200

  • Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-ansible-posix-0:1.2.0-1.3.el9ost.noarch as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-ansible-posix-0:1.2.0-1.3.el9ost.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-ansible-posix-0:2.0.0-1.el10cp.noarch as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-ansible-posix-0:2.0.0-1.el10cp.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-community-general-0:10.7.3-1.el10cp.noarch as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-community-general-0:10.7.3-1.el10cp.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-community-general-0:4.0.0-1.1.el9ost.noarch as a component of Red Hat Ceph Storage 9.0 Tools
  • ansible-collection-community-general-0:4.0.0-1.1.el9ost.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-2:20.1.0-144.el10cp.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-2:20.1.0-144.el9cp.src as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el10cp.aarch64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el10cp.ppc64le as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el10cp.s390x as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el10cp.x86_64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el9cp.aarch64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el9cp.ppc64le as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el9cp.s390x as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-2:20.1.0-144.el9cp.x86_64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el10cp.aarch64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el10cp.ppc64le as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el10cp.s390x as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el10cp.x86_64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el9cp.aarch64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el9cp.ppc64le as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el9cp.s390x as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-base-debuginfo-2:20.1.0-144.el9cp.x86_64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-common-2:20.1.0-144.el10cp.aarch64 as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-common-2:20.1.0-144.el10cp.ppc64le as a component of Red Hat Ceph Storage 9.0 Tools
  • ceph-common-2:20.1.0-144.el10cp.s390x as a component of Red Hat Ceph Storage 9.0 Tools
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Red Hat Product Security does not have any recommended mitigations at this time. Please update as patched versions become available.

🔗 References (292)