Red Hat Security Advisory: Red Hat Ceph Storage
🔗 CVE IDs covered (10)
📋 Description
CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2022-27191 — golang: crash in a golang.org/x/crypto/ssh server CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-48916 — ceph: rhceph-container: Authentication bypass in CEPH RadosGW CVE-2025-30156 — kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass CVE-2026-21721 — grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation CVE-2026-39944 — ceph: ceph: RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation CVE-2026-41680 — marked: Marked: Denial of Service via specific input sequence CVE-2026-50152 — ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users CVE-2026-54330 — ceph: ceph: RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation
🎯 Affected products29
- Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:25c748548e1514f7ddde641f081497cd94a71518de62a141cf0c7fef6fa5a00c_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:606c3c9fb7e17de1b3e5981c0e8fe060fd4db6a94c04840008ef79bcf50386b0_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:80a251fa12bc350ca8aab1dd9054f86768119b20fc38b484c17af50805d19b98_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:c19e1ec7ad2e588d51e5934fb97c64965e948479aed4751939e8398cd0f008f1_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:17050d0ebc49274ce706e4639ca6502f3750127893bc534314a86958e581553a_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:22d113b46e255d4683a4ae929ede3e14e1c75495895abeb9636a9f8f6f8cc2eb_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:2a0ef10019c0d9fc2ba03b3ffbffe48d352f62d4124155dae4d166498b3eb1c7_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:4ee6f59422288387c4acff7da0f8cb4c12bfe94690da4986f1358c13b0295008_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:332cf62937c53b1495812dcb3fd8d39df372572c6cf3b6fe7e8ea9aa0a05dd5b_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:54b27c84bb316bae524d131fbf51ca7fc38784e9f3384137b660e961a71dc340_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:71361c1aba8442e9e21af026d3a73c2f5124ef472766545f55f77dfe7d033bbe_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:d20e25c02cad018ced68410396b1385c6ee201fbfe61590f3a80ed0ad9c660b3_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:2b2d9fc84f4cc9827ca03406a1ee778f11c8f996cec379c12465dfae21bf5832_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:5496d6b783ed5b48d6ba889d7e656d8fb9c47fc87149fce88cb1ce5e18970f20_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:7a5133f2adbd7d8d7953484c53eec5914d9fa055c7327b474e843fa2e083a7ed_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:fa0c153625d122b206fab5d14adb467dacf192212e147772ad5d6efee016adac_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:05abd08e664508106bb57a18b75147007276a9368676a919a61080930c478c51_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:52f5863ea71c31cf51b9f75f57ef362b99217d75be9896fcb453a2d1e2755f54_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:95c1012aebbf1d2f11cb64830378a86459e47111dfd3b3d3f0747c463fcec6b3_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:cc52ebdd7b4d1252b71a8fbeb94e2cd6f842054c1edceebfe51efef48a62ea54_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:10f7a403879682ffa0e674ebf5bd537bd36da428d981712ada80f20c71257822_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:32887d89e509c051aafe9918a09b410b50d568396d7bb55978cdab3b78d34156_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:7f2e0116d878ba773de63badc8bc9f178855a095002bed80cc536aff319617a3_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:c7b2e91a1aea2c255e8b9315f2f6fecbe7a708d6a2b2ea0b8cef5e20267b5ab2_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:47877aea3d5142a42b01dbe8108ead76b55c92fac60433816dce699bfde9ec27_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:8c4bfcd647337733f6a1c05957d7b8bb8dff61a0ac33d7cc3a4b22717030354f_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:d804229ee55b5eb1a99a95a71bad2de5a1675783da6fd661d85ede1eca1ced70_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:e4bf3c69d6a14eb59d794dcbb94d8cc64940ddb798595c2d1f1d2b86d0cf5240_amd64 as a component of Red Hat Ceph Storage 8.1
✅ Remediation
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 ~~~ NOTE: The crypto-policies workaround requires RHEL 8.5 or newer. Customers (for older RHEL 8 releases) who cannot immediately update crypto-policies packages may manually configuring Ciphers and MACs directly in /etc/ssh/sshd_config and ssh_config (as used for "RHEL-7") method documented https://access.redhat.com/solutions/7066001 ~~~~ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, Red Hat recommends isolating the Ceph messenger protocol to dedicated internal networks with strict access controls, limiting exposure to potential attackers. Administrators should audit and minimize the number of CephX client credentials in circulation and enforce strong credential management to reduce the risk of low-privilege key compromise. Where possible, deploy msgr2 with on-wire encryption to reduce passive sniffing exposure. It is strongly advised to apply vendor-supplied patches as soon as they are released, upgrade to fixed Ceph versions (Tentacle 20.2.4 or later), and rotate all CephX keys to the new AES-256-CTS-HMAC-SHA384-192 cipher type, prioritizing server-side keys. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, Red Hat products that utilize the 'marked' library should be configured to process markdown content only from trusted sources. If markdown rendering is not a critical function, consider disabling or restricting its use within the application's configuration to reduce exposure.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:79243
- externalhttps://access.redhat.com/security/cve/CVE-2021-43565
- externalhttps://access.redhat.com/security/cve/CVE-2022-27191
- externalhttps://access.redhat.com/security/cve/CVE-2023-48795
- externalhttps://access.redhat.com/security/cve/CVE-2024-48916
- externalhttps://access.redhat.com/security/cve/CVE-2025-30156
- externalhttps://access.redhat.com/security/cve/CVE-2026-21721
- externalhttps://access.redhat.com/security/cve/CVE-2026-39944
- externalhttps://access.redhat.com/security/cve/CVE-2026-41680
- externalhttps://access.redhat.com/security/cve/CVE-2026-50152
- externalhttps://access.redhat.com/security/cve/CVE-2026-54330
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ceph_storage/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_79243.json