Skip to main content
EPSS 0.3%top 82%

Red Hat Security Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog.

0
High
Published: 06/23/2025 (06/23/2025, 02:17:34 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. This new container image is based on Red Hat Ceph Storage 7.1 and Red Hat Enterprise Linux 8.10, 9.4, 9.5. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Ceph Storage Release Notes for information on the most significant of these changes: https://docs.redhat.com/en/documentation/red_hat_ceph_storage/7/html/7.1_release_notes All users of Red Hat Ceph Storage are advised to pull these new images from the Red Hat Ecosystem catalog, which provides numerous bug fixes.

Affected software

Affected versions
>=7.1 <8.2>=8.1 <8.2Red HatRed Hat Ceph StorageRed Hat Ceph Storage 8.1 Toolsppc64lerhceph/grafana-rhel9@sha256:9003f917a389ec64f27685a218eb29564065c051f709110faba83e7bfdfcb714_ppc64leRed Hat Ceph Storage 7.1 Toolsamd64rhceph/grafana-rhel9@sha256:e6986670487df0bed88d84cbe6cbb24d218c61b4053da2fe49128d177e818e02_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:03:10 UTC

Technical Analysis

Red Hat Ceph Storage, a scalable software-defined storage platform, has updated container images based on versions 7.1 and 8.1 of Red Hat Ceph Storage combined with Red Hat Enterprise Linux 8.10, 9.4, 9.5, and later. These updates address multiple security vulnerabilities including CVE-2024-24557 (moby classic builder cache poisoning), CVE-2024-45338 (non-linear parsing in golang.org/x/net/html), CVE-2024-53382 (DOM clobbering in prismjs), CVE-2025-22865 (panic in crypto/x509), CVE-2025-22868 (memory consumption in golang.org/x/oauth2/jws), CVE-2025-22871 (HTTP request smuggling in net/http), and CVE-2025-30204 (excessive memory allocation in golang-jwt/jwt). The vendor advisory strongly recommends users pull the updated container images from the Red Hat Ecosystem Catalog to apply these fixes. The advisories also provide references to release notes and instructions for applying updates.

Potential Impact

The vulnerabilities fixed in these updates include cache poisoning, code execution risks, parsing errors leading to potential crashes or memory issues, DOM clobbering, and HTTP request smuggling. These issues could potentially allow attackers to execute arbitrary code, cause denial of service, or manipulate data within the affected container environments. The impact is significant enough for Red Hat to classify the advisory as important and the severity as high.

Mitigation Recommendations

Red Hat has released updated container images for Red Hat Ceph Storage 7.1 and 8.1 that include fixes for the listed vulnerabilities. Users should pull the updated container images from the Red Hat Ecosystem Catalog as the primary remediation step. Before applying these updates, users should ensure all previously released errata relevant to their systems have been applied. Detailed update instructions and supported configurations are available in the Red Hat knowledge base articles linked in the advisory. No additional mitigation steps are indicated beyond applying these updated container images.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:11749
Cve Count
7
Additional Cves
["CVE-2024-45338","CVE-2024-53382","CVE-2025-22865","CVE-2025-22868","CVE-2025-22871","CVE-2025-30204"]

Threat ID: 6a160976e29bf47b506409ca

Added to database: 05/26/2026, 20:58:30 UTC

Last enriched: 08/14/2026, 23:03:10 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 68

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses