Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security and bug fix updates
🔗 CVE IDs covered (11)
📋 Description
CVE-2021-23358 — nodejs-underscore: Arbitrary code execution via the template function CVE-2022-34749 — mistune: catastrophic backtracking CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-31884 — pybind: Improper use of Pybind CVE-2024-47866 — rgw: RGW DoS attack with empty HTTP header in S3 object copy CVE-2024-51744 — golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2025-26791 — dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-52555 — ceph: privilege escalation by unprivileged users in a ceph-fuse mounted CephFS CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
🎯 Affected products200
- Red Hat Ceph Storage 7.1 Tools
- ceph-2:18.2.1-381.el8cp.src as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-2:18.2.1-381.el9cp.src as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-2:18.2.1-381.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-2:18.2.1-381.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-2:18.2.1-381.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-debuginfo-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-debuginfo-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-debuginfo-2:18.2.1-381.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-debuginfo-2:18.2.1-381.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-base-debuginfo-2:18.2.1-381.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-2:18.2.1-381.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-2:18.2.1-381.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-2:18.2.1-381.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-debuginfo-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-debuginfo-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-debuginfo-2:18.2.1-381.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-debuginfo-2:18.2.1-381.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-common-debuginfo-2:18.2.1-381.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debuginfo-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debuginfo-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debuginfo-2:18.2.1-381.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debuginfo-2:18.2.1-381.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debuginfo-2:18.2.1-381.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debugsource-2:18.2.1-381.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- ceph-debugsource-2:18.2.1-381.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Red Hat Product Security does not have any recommended mitigations at this time. Please update as patched versions become available.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2026:2769
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944286
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2112230
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2323735
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2329426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2360974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372611
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2389907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392861
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2404076
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2404656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2404880
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2412237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2412474
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414844
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416314
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2432069
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2769.json