Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 51%

Red Hat Security Advisory: New container image: rhceph-9.0

0
High
Published: 06/16/2026 (06/16/2026, 16:32:52 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 9.0. This release updates to the latest version.

Affected software

Affected versions
Red HatRed Hat Ceph StorageRed Hat Ceph Storage 9amd64registry.redhat.io/rhceph/alloy-rhel10@sha256:b839e918e2b695ee22e954273f016c6ecdebc1f6048e538560b7162f21f9b83a_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 12:29:13 UTC

Technical Analysis

The Red Hat Storage Ceph container images have been updated to version 9.0, incorporating the latest ubi9 base image and Ceph 9.0. This release addresses multiple security vulnerabilities, including CVE-2024-55565 and several CVEs from 2025. The advisory does not specify detailed technical vulnerability descriptions or fixes but provides a new container image for deployment. No known exploits in the wild are reported. The update is distributed as a new container image available via Red Hat's container registry.

Potential Impact

The vulnerabilities addressed are rated as high severity by Red Hat Product Security. The specific CVEs include issues related to various CWE categories such as CWE-835 (Loop with Unreachable Exit Condition), CWE-125 (Out-of-bounds Read), CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-22 (Path Traversal), CWE-1321 (Improper Handling of Unicode Encoding), and CWE-78 (OS Command Injection). These could potentially allow attackers to cause denial of service, unauthorized data access, or command execution if exploited. However, no known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat recommends deploying the updated container image rhceph-9.0 available from the Red Hat container registry using the "podman pull" command. This update replaces previous versions and addresses the listed vulnerabilities. No additional patches or fixes are currently provided. Users should update to this new container image to mitigate the vulnerabilities. Patch status is effectively managed by updating to this new container image version.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:10990
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a1f4e9fe29bf47b500871d2

Added to database: 06/02/2026, 21:43:59 UTC

Last enriched: 07/30/2026, 12:29:13 UTC

Last updated: 07/31/2026, 21:28:45 UTC

Views: 53

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses