Red Hat Security Advisory: Red Hat Ceph Storage
🔗 CVE IDs covered (14)
📋 Description
CVE-2025-9820 — gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function CVE-2025-12801 — nfs-utils: rpc.mountd in the nfs-utils privilege escalation CVE-2025-14831 — gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory CVE-2025-15366 — cpython: IMAP command injection in user-controlled commands CVE-2025-15367 — cpython: POP3 command injection in user-controlled commands CVE-2026-0861 — glibc: Integer overflow in memalign leads to heap corruption CVE-2026-0865 — cpython: wsgiref.headers.Headers allows header newline injection in Python CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query CVE-2026-1299 — cpython: email header injection due to unquoted newlines CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:5606
- externalhttps://access.redhat.com/security/cve/CVE-2025-12801
- externalhttps://access.redhat.com/security/cve/CVE-2025-14831
- externalhttps://access.redhat.com/security/cve/CVE-2025-15281
- externalhttps://access.redhat.com/security/cve/CVE-2025-15366
- externalhttps://access.redhat.com/security/cve/CVE-2025-15367
- externalhttps://access.redhat.com/security/cve/CVE-2025-9820
- externalhttps://access.redhat.com/security/cve/CVE-2026-0861
- externalhttps://access.redhat.com/security/cve/CVE-2026-0865
- externalhttps://access.redhat.com/security/cve/CVE-2026-0915
- externalhttps://access.redhat.com/security/cve/CVE-2026-1299
- externalhttps://access.redhat.com/security/cve/CVE-2026-22695
- externalhttps://access.redhat.com/security/cve/CVE-2026-22801
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-25646
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ceph_storage/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5606.json