CVE-2025-6395: Red Hat Ceph Storage 7

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Affected products

  • Red Hat Red Hat Ceph Storage 7: before 7 (fixed in 7)
  • Red Hat Red Hat Discovery 2: before 2.3.0-1760554384 (fixed in 2.3.0-1760554384)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.8.9-9.el10_0.14 (fixed in 0:3.8.9-9.el10_0.14)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 0:3.6.16-8.el8_10.4 (fixed in 0:3.6.16-8.el8_10.4)
  • Red Hat Red Hat Enterprise Linux 9: before 0:3.8.3-6.el9_6.2 (fixed in 0:3.8.3-6.el9_6.2)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.7.6-21.el9_2.4 (fixed in 0:3.7.6-21.el9_2.4)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:3.8.3-4.el9_4.4 (fixed in 0:3.8.3-4.el9_4.4)
  • Red Hat Red Hat Insights Proxy 1.5: before 1.5.7-1759331989 (fixed in 1.5.7-1759331989)
  • Red Hat Red Hat Openshift Container Platform 4
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.5
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp: from V3.1.5
  • Siemens Siplus s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.5

Published 2025-07-10. Last modified 2026-09-01.