https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/errata/RHSA-2025:4238
https://bugzilla.redhat.com/show_bug.cgi?id=2164077
https://bugzilla.redhat.com/show_bug.cgi?id=2246440
https://bugzilla.redhat.com/show_bug.cgi?id=2247402
https://bugzilla.redhat.com/show_bug.cgi?id=2257935
https://bugzilla.redhat.com/show_bug.cgi?id=2266793
https://bugzilla.redhat.com/show_bug.cgi?id=2269342
https://bugzilla.redhat.com/show_bug.cgi?id=2271596
https://bugzilla.redhat.com/show_bug.cgi?id=2275475
https://bugzilla.redhat.com/show_bug.cgi?id=2283576
https://bugzilla.redhat.com/show_bug.cgi?id=2290721
https://bugzilla.redhat.com/show_bug.cgi?id=2297966
https://bugzilla.redhat.com/show_bug.cgi?id=2299482
https://bugzilla.redhat.com/show_bug.cgi?id=2300252
https://bugzilla.redhat.com/show_bug.cgi?id=2303084
https://bugzilla.redhat.com/show_bug.cgi?id=2303112
https://bugzilla.redhat.com/show_bug.cgi?id=2303415
https://bugzilla.redhat.com/show_bug.cgi?id=2307933
https://bugzilla.redhat.com/show_bug.cgi?id=2308166
https://bugzilla.redhat.com/show_bug.cgi?id=2314213
https://bugzilla.redhat.com/show_bug.cgi?id=2315686
https://bugzilla.redhat.com/show_bug.cgi?id=2315936
https://bugzilla.redhat.com/show_bug.cgi?id=2317530
https://bugzilla.redhat.com/show_bug.cgi?id=2317562
https://bugzilla.redhat.com/show_bug.cgi?id=2318288
https://bugzilla.redhat.com/show_bug.cgi?id=2321292
https://bugzilla.redhat.com/show_bug.cgi?id=2326137
https://bugzilla.redhat.com/show_bug.cgi?id=2337305
https://bugzilla.redhat.com/show_bug.cgi?id=2337309
https://bugzilla.redhat.com/show_bug.cgi?id=2343973
https://bugzilla.redhat.com/show_bug.cgi?id=2345553
https://bugzilla.redhat.com/show_bug.cgi?id=2345559
https://bugzilla.redhat.com/show_bug.cgi?id=2345561
https://bugzilla.redhat.com/show_bug.cgi?id=2355037
Severity: High
ID: 237014
File Name: redhat-RHSA-2025-4238.nasl
Version: 1.1
Type: local
Agent: unix
Family: Red Hat Local Security Checks
Published: 5/21/2025
Updated: 5/21/2025
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Factor: High
Score: 7.4
Vendor Severity: Important
Risk Factor: High
Base Score: 9.4
Temporal Score: 7
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
CVSS Score Source: CVE-2024-48916
Risk Factor: High
Base Score: 7.1
Temporal Score: 6.2
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
CVSS Score Source: CVE-2024-47191
CPE: cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:ceph-common, p-cpe:/a:redhat:enterprise_linux:ceph-selinux, p-cpe:/a:redhat:enterprise_linux:librados2, p-cpe:/a:redhat:enterprise_linux:librbd1, p-cpe:/a:redhat:enterprise_linux:ceph-base, p-cpe:/a:redhat:enterprise_linux:ceph-fuse, p-cpe:/a:redhat:enterprise_linux:libcephfs-devel, p-cpe:/a:redhat:enterprise_linux:libcephfs2, p-cpe:/a:redhat:enterprise_linux:librados-devel, p-cpe:/a:redhat:enterprise_linux:libradosstriper1, p-cpe:/a:redhat:enterprise_linux:librbd-devel, p-cpe:/a:redhat:enterprise_linux:librgw-devel, p-cpe:/a:redhat:enterprise_linux:librgw2, p-cpe:/a:redhat:enterprise_linux:libradospp-devel, p-cpe:/a:redhat:enterprise_linux:python3-ceph-argparse, p-cpe:/a:redhat:enterprise_linux:python3-cephfs, p-cpe:/a:redhat:enterprise_linux:python3-rados, p-cpe:/a:redhat:enterprise_linux:python3-rbd, p-cpe:/a:redhat:enterprise_linux:python3-rgw, p-cpe:/a:redhat:enterprise_linux:rbd-nbd, p-cpe:/a:redhat:enterprise_linux:ceph-immutable-object-cache, p-cpe:/a:redhat:enterprise_linux:ceph-resource-agents, p-cpe:/a:redhat:enterprise_linux:cephadm, p-cpe:/a:redhat:enterprise_linux:cephfs-top, p-cpe:/a:redhat:enterprise_linux:python3-ceph-common, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:ceph-mib, p-cpe:/a:redhat:enterprise_linux:ceph, p-cpe:/a:redhat:enterprise_linux:liboath, p-cpe:/a:redhat:enterprise_linux:oath-toolkit
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu
Exploit Ease: No known exploits are available
Patch Publication Date: 4/28/2025
Vulnerability Publication Date: 10/8/2024
CVE: CVE-2024-47191, CVE-2024-48916