RHSA-2025:15841HighCVSS 7.5

Red Hat Security Advisory: Red Hat Enterprise Linux AI 1.5 (NVIDIA)

Published
September 15, 2025
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-47277 — vllm: vLLM Allows Remote Code Execution via PyNcclPipe Communication Service CVE-2025-48379 — python-pillow: pillow: Pillow DDS Heap Buffer Overflow

🎯 Affected products3

  • Red Hat Enterprise Linux AI 1.5
  • registry.redhat.io/rhelai1/bootc-nvidia-rhel9@sha256:4a40fcdfb64b4cec6dfb0d0ee5c475fc89124ce80d911dd85f5951238b6c980c_arm64 as a component of Red Hat Enterprise Linux AI 1.5
  • registry.redhat.io/rhelai1/bootc-nvidia-rhel9@sha256:539b3bb9fc9330fe7237b7292ce8b112a38dd22bfff9f090e82a518f9b2f2376_amd64 as a component of Red Hat Enterprise Linux AI 1.5

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2025:15841 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)