Red Hat Security Advisory: New container image: rhceph-9.0
The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 9.0. This release updates to the latest version.
AI Analysis
Technical Summary
The Red Hat Storage Ceph container images have been updated to version 9.0, incorporating the latest ubi9 base image and Ceph 9.0. This release addresses multiple security vulnerabilities, including CVE-2024-55565 and several CVEs from 2025. The advisory does not specify detailed technical vulnerability descriptions or fixes but provides a new container image for deployment. No known exploits in the wild are reported. The update is distributed as a new container image available via Red Hat's container registry.
Potential Impact
The vulnerabilities addressed are rated as high severity by Red Hat Product Security. The specific CVEs include issues related to various CWE categories such as CWE-835 (Loop with Unreachable Exit Condition), CWE-125 (Out-of-bounds Read), CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-22 (Path Traversal), CWE-1321 (Improper Handling of Unicode Encoding), and CWE-78 (OS Command Injection). These could potentially allow attackers to cause denial of service, unauthorized data access, or command execution if exploited. However, no known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat recommends deploying the updated container image rhceph-9.0 available from the Red Hat container registry using the "podman pull" command. This update replaces previous versions and addresses the listed vulnerabilities. No additional patches or fixes are currently provided. Users should update to this new container image to mitigate the vulnerabilities. Patch status is effectively managed by updating to this new container image version.
Red Hat Security Advisory: New container image: rhceph-9.0
Description
The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 9.0. This release updates to the latest version.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Storage Ceph container images have been updated to version 9.0, incorporating the latest ubi9 base image and Ceph 9.0. This release addresses multiple security vulnerabilities, including CVE-2024-55565 and several CVEs from 2025. The advisory does not specify detailed technical vulnerability descriptions or fixes but provides a new container image for deployment. No known exploits in the wild are reported. The update is distributed as a new container image available via Red Hat's container registry.
Potential Impact
The vulnerabilities addressed are rated as high severity by Red Hat Product Security. The specific CVEs include issues related to various CWE categories such as CWE-835 (Loop with Unreachable Exit Condition), CWE-125 (Out-of-bounds Read), CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-22 (Path Traversal), CWE-1321 (Improper Handling of Unicode Encoding), and CWE-78 (OS Command Injection). These could potentially allow attackers to cause denial of service, unauthorized data access, or command execution if exploited. However, no known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat recommends deploying the updated container image rhceph-9.0 available from the Red Hat container registry using the "podman pull" command. This update replaces previous versions and addresses the listed vulnerabilities. No additional patches or fixes are currently provided. Users should update to this new container image to mitigate the vulnerabilities. Patch status is effectively managed by updating to this new container image version.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:10990
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a1f4e9fe29bf47b500871d2
Added to database: 06/02/2026, 21:43:59 UTC
Last enriched: 07/30/2026, 12:29:13 UTC
Last updated: 07/31/2026, 21:28:45 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.