Red Hat Security Advisory: Red Hat Ceph Storage 8.1 security and bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-10790 — taffy: taffydb: Internal Property Tampering CVE-2022-34749 — mistune: catastrophic backtracking CVE-2024-31884 — pybind: Improper use of Pybind CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map
🎯 Affected products200
- Red Hat Ceph Storage 8.1 Tools
- ceph-2:19.2.1-331.el9cp.src as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-debuginfo-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-debuginfo-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-debuginfo-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-base-debuginfo-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-debuginfo-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-debuginfo-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-debuginfo-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-common-debuginfo-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debuginfo-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debuginfo-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debuginfo-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debuginfo-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debugsource-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debugsource-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debugsource-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-debugsource-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-exporter-debuginfo-2:19.2.1-331.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-exporter-debuginfo-2:19.2.1-331.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-exporter-debuginfo-2:19.2.1-331.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
- ceph-exporter-debuginfo-2:19.2.1-331.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2026:2711
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2112230
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151848
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2320312
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2325394
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2356539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2389907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2389970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2406674
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2407258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2411968
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2412473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2413969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414843
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2415380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2415838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416558
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416987
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2417015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2417688
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2421434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2421706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2421743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2423404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2424278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2427566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2431960
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2432068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2432370
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2711.json