Red Hat Security Advisory: New container image: rhceph-9.0
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-47914 — golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages CVE-2025-58181 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication CVE-2025-59343 — tar-fs: tar-fs symlink validation bypass CVE-2025-64718 — js-yaml: js-yaml prototype pollution in merge CVE-2025-64756 — glob: glob: Command Injection Vulnerability via Malicious Filenames
🎯 Affected products29
- Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/alloy-rhel10@sha256:4275a746d036f4a674f2a41c584d1061160392818c0bf47f1e831034654c3c26_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/alloy-rhel10@sha256:6cc5bc1fe92aecfb16bb3b6ccf833d06dc4484f8f7c9ffb7bedc3b3e49ace7b6_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/alloy-rhel10@sha256:b1c91e9df4b0bb9437394b92444480d6417a39bb46c8474d8c8027ab01732ca4_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/alloy-rhel10@sha256:b839e918e2b695ee22e954273f016c6ecdebc1f6048e538560b7162f21f9b83a_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/grafana-rhel10@sha256:10d6f4417f63579b5ad0c2642e68049bf4b0cbc07393f05f5ccd6d93ad9b4551_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/grafana-rhel10@sha256:b413d37ad30595df599c3aa8c7dbfad08acc6fa9a59e5300d6e66746d0ed7c92_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/grafana-rhel10@sha256:ed69dc576cf04d5ed270a4a271aa89a5476b46d58a85c937f1c63d6680b08b73_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/grafana-rhel10@sha256:f73c95e3c84116b5fb7320af22e69d252df69d4559f4ce7bdfd59f42902338c7_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/keepalived-rhel10@sha256:41e5ab72e781b1baa72b7158b2fb6af247c52042f828b496a15ff78adde413a3_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/keepalived-rhel10@sha256:498e05a439ac63b3a42882dd908d086078f697ff8c29dc2effedec8b26dd6521_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/keepalived-rhel10@sha256:5b0ca20174d1c6cdb3229bf625a906acf64509575c3092895e341ec301c5e92e_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/keepalived-rhel10@sha256:a214782e432451ca21a5042abd90bf44c57ed01563dfa4d1b81ef72f38ef2265_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:09758d53ef928e8740a95a31572462681a0f70c1c2a6eaa6a72a45fddf4538b7_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:5f4554659280456cba1fb0078dceb46964a9759f1c5ec0a8fa5d4a6f2bc4889f_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:8afff49beebd4fd88ccf687a421bca80c6d3295a38ef9fcef92ab2049d5f78db_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:be1e659b4f556e0dd65aa36141fa4ab940c5bdee4cf96e1425addb95330c9a09_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-9-rhel9@sha256:1eb37889b6fd96e9bb95257e30918212f290caf50d9dbe76b6e46af067cdeda6_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-9-rhel9@sha256:8705162c817322ffdabfee74c5fec3ce4f37be667f46634981cb66db0354ef10_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-9-rhel9@sha256:b73e4453cb4a353d458ce8fe0641dfd1314ba383d836f1631e0cca5d9ffdca4e_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-9-rhel9@sha256:fa557386c42c9144dcef16957fc0f02b6e631d037cb982c70a043ce11d760556_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:01f59a1b847d03122126fb3db62daa1e924d2bed5da9506061013800085c100b_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:10ed1c8ea558924ddfa1d3ab6a43d34a6edd16e09dac44d593487bc22b2fc7fc_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:94f30db2064d0d62776af04715a67f90d3fb852855c123eff51285122e296328_s390x as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:f58c4b24482819abd2cb67f30d3e1034d61dd85a043f76bc3f487e48941bd201_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/snmp-notifier-rhel10@sha256:087c99d8838e9c2bd9a298fc320e954ea27203bbceaced070930c87f8a6581a8_arm64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/snmp-notifier-rhel10@sha256:94a7dea2910f1f440c42c143f930886b529b00a3d6a0eab08d06596f157977a9_ppc64le as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/snmp-notifier-rhel10@sha256:e40d93d9d76fe8aa344905015d75ae13f94622f6e64de432b73af1930136f8de_amd64 as a component of Red Hat Ceph Storage 9
- registry.redhat.io/rhceph/snmp-notifier-rhel10@sha256:e5244c1382ad165701a9e156618d8452d78e70675d33668cbdaf6d93f99a58f1_s390x as a component of Red Hat Ceph Storage 9
✅ Remediation
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, avoid using the `glob` command-line interface with the `-c` or `--cmd` option when processing filenames from untrusted sources. If programmatic use of `glob` is necessary, ensure that filenames are thoroughly sanitized before being passed to commands executed with shell interpretation enabled.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:26411
- externalhttps://access.redhat.com/security/cve/CVE-2024-55565
- externalhttps://access.redhat.com/security/cve/CVE-2025-47913
- externalhttps://access.redhat.com/security/cve/CVE-2025-47914
- externalhttps://access.redhat.com/security/cve/CVE-2025-58181
- externalhttps://access.redhat.com/security/cve/CVE-2025-59343
- externalhttps://access.redhat.com/security/cve/CVE-2025-64718
- externalhttps://access.redhat.com/security/cve/CVE-2025-64756
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ceph_storage/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_26411.json