Skip to main content
EPSS 0.2%top 89%

Red Hat Security Advisory: Red Hat Ceph Storage

0
High
Published: 03/24/2026 (03/24/2026, 10:00:07 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 8.1. This release updates to the latest version.

Affected software

Affected versions
Red HatRed Hat Ceph StorageRed Hat Ceph Storage 8amd64registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:1160569002c25d3d349bbe41b57eeffade438853d3419edca01813227440f414_amd64Red Hat Insights proxyRed Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:86431fdb1ba7fa0cbc8e82cc5fe518b7c0946b8847991fc95604b1d1cfd45e06_amd64Red Hat Hardened Imagesaarch64gnutls-main@aarch64Red Hat OpenShift EnterpriseMiddleware Containers for OpenShiftrhpam-7/rhpam-businesscentral-monitoring-rhel8@sha256:92df715c896f06f6aa93b631bd62e3a146bad3cd08666cbab955d5cccdad0ea0_amd643.8.13.8.23.8.33.8.43.8.53.8.63.8.73.8.83.8.93.8.10Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)Red Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)s390x

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:08:14 UTC

Technical Analysis

The Red Hat RHEL-8 based Middleware Containers container images were updated to fix several security issues documented in multiple Red Hat Security Advisories (RHSA-2026:11077, RHSA-2026:7667, RHSA-2026:8534, RHSA-2026:9745). The vulnerabilities addressed include CVE-2025-10158 (rsync out-of-bounds array access), CVE-2025-9820 (gnutls stack-based buffer overflow), CVE-2025-14831 (gnutls denial of service), CVE-2026-3497 (openssh GSSAPI information disclosure or denial of service), CVE-2026-27135 (nghttp2 denial of service), CVE-2026-4424 (libarchive information disclosure), CVE-2026-4519 (python command-line option injection), CVE-2026-5121 (libarchive arbitrary code execution), CVE-2026-6100 (python use-after-free leading to arbitrary code execution or information disclosure), and CVE-2026-4786 (python command injection). These fixes are backported into updated container images. Users of these images should upgrade and rebuild dependent containers to mitigate these issues. The vendor advisory confirms the availability of updated images and patches.

Potential Impact

The vulnerabilities collectively allow for potential out-of-bounds memory access, buffer overflows, denial of service conditions, information disclosure, command injection, and arbitrary code execution within the affected container images. This can lead to unauthorized access, service disruption, or execution of malicious code within environments running these containers. The impact is rated high due to the range of critical issues fixed.

Mitigation Recommendations

Red Hat has released updated RHEL-8 based Middleware Containers container images containing backported patches that address these vulnerabilities. Users are strongly advised to upgrade to these updated images and rebuild all container images that depend on them. No alternative mitigations are specified. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:13812
Cve Count
10
Additional Cves
["CVE-2025-10158","CVE-2025-14831","CVE-2026-3497","CVE-2026-4424","CVE-2026-4519","CVE-2026-4786","CVE-2026-5121","CVE-2026-6100","CVE-2026-27135"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a160977e29bf47b50643201

Added to database: 05/26/2026, 20:58:31 UTC

Last enriched: 08/10/2026, 20:08:14 UTC

Last updated: 09/14/2026, 10:24:45 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:5606https://access.redhat.com/security/cve/CVE-2025-12801https://access.redhat.com/security/cve/CVE-2025-14831https://access.redhat.com/security/cve/CVE-2025-15281https://access.redhat.com/security/cve/CVE-2025-15366https://access.redhat.com/security/cve/CVE-2025-15367https://access.redhat.com/security/cve/CVE-2025-9820https://access.redhat.com/security/cve/CVE-2026-0861https://access.redhat.com/security/cve/CVE-2026-0865https://access.redhat.com/security/cve/CVE-2026-0915https://access.redhat.com/security/cve/CVE-2026-1299https://access.redhat.com/security/cve/CVE-2026-22695https://access.redhat.com/security/cve/CVE-2026-22801https://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-25646https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_ceph_storage/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7477https://images.redhat.com/https://access.redhat.com/security/cve/CVE-2025-32990https://access.redhat.com/security/cve/CVE-2025-32989https://access.redhat.com/security/cve/CVE-2025-32988https://access.redhat.com/security/cve/CVE-2026-1584Canonical URLhttps://access.redhat.com/errata/RHSA-2026:4655Canonical URLhttps://access.redhat.com/errata/RHSA-2026:13812https://access.redhat.com/security/updates/classification/#importanthttps://access.redhat.com/errata/RHSA-2026:11077https://access.redhat.com/errata/RHSA-2026:7667https://access.redhat.com/errata/RHSA-2026:8534https://access.redhat.com/errata/RHSA-2026:9745https://errata.engineering.redhat.com/advisory/165062https://access.redhat.com/containers2392528241563724231772447085244875424490062449649245294524579322458049Canonical URLReference 47Reference 48Reference 49Reference 50Reference 51Reference 52Reference 53Reference 54Reference 55Reference 56https://access.redhat.com/security/updates/classification/#moderateCanonical URLCanonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses