RHSA-2025:21068HighCVSS 7.5

Red Hat Security Advisory: Red Hat Ceph Storage 8.1 bug fix update

Published
November 12, 2025
Last Modified
August 15, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-47866 — rgw: RGW DoS attack with empty HTTP header in S3 object copy

🎯 Affected products168

  • Red Hat Ceph Storage 8.1 Tools
  • ceph-2:19.2.1-292.el9cp.src as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-base-debuginfo-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-common-debuginfo-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debuginfo-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-debugsource-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-exporter-debuginfo-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-debuginfo-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-debuginfo-2:19.2.1-292.el9cp.s390x as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-fuse-debuginfo-2:19.2.1-292.el9cp.x86_64 as a component of Red Hat Ceph Storage 8.1 Tools
  • ceph-immutable-object-cache-2:19.2.1-292.el9cp.ppc64le as a component of Red Hat Ceph Storage 8.1 Tools
  • +138 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (19)