RHSA-2026:79101HighCVSS 9.1

Red Hat Security Advisory: Red Hat Ceph Storage 8.1 security and bug fix updates

Published
October 8, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-48916 — ceph: rhceph-container: Authentication bypass in CEPH RadosGW CVE-2025-30156 — kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass CVE-2026-39944 — ceph: ceph: RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation CVE-2026-50152 — ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users CVE-2026-54330 — ceph: ceph: RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation

🎯 Affected products200

  • Red Hat Ceph Storage 8.1 Tools
  • ceph-2:19.2.1-423.el9cp.src as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-423.el9cp.aarch64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-423.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-423.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-423.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 ~~~ NOTE: The crypto-policies workaround requires RHEL 8.5 or newer. Customers (for older RHEL 8 releases) who cannot immediately update crypto-policies packages may manually configuring Ciphers and MACs directly in /etc/ssh/sshd_config and ssh_config (as used for "RHEL-7") method documented https://access.redhat.com/solutions/7066001 ~~~~ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, Red Hat recommends isolating the Ceph messenger protocol to dedicated internal networks with strict access controls, limiting exposure to potential attackers. Administrators should audit and minimize the number of CephX client credentials in circulation and enforce strong credential management to reduce the risk of low-privilege key compromise. Where possible, deploy msgr2 with on-wire encryption to reduce passive sniffing exposure. It is strongly advised to apply vendor-supplied patches as soon as they are released, upgrade to fixed Ceph versions (Tentacle 20.2.4 or later), and rotate all CephX keys to the new AES-256-CTS-HMAC-SHA384-192 cipher type, prioritizing server-side keys. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)