The new Ceph versions address a total of four security vulnerabilities (CVEs) affecting, among other things, CephX authentication, the RADOS Gateway (RGW), and the Ceph Monitor. CVE-2025-30156 is particularly relevant: This vulnerability allows an authentication bypass and requires CephX keys to be rotated as part of the update. To address this, Ceph is introducing a new key type called aes256k.
For cephadm and Rook, parts of the key rotation are automated; however, special attention must be paid to client keys and existing OpenStack integrations. Additional upgrade steps apply to RGW multisite environments. Ceph strongly recommends upgrading existing installations to Squid 19.2.6 or Tentacle 20.2.4 as soon as possible.
With PVE 9.2 and Ceph 20.2.4, RBD operations may currently fail due to the removal of the --auth_supported option. An official bug report has since been filed regarding this issue.