Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.1
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-4519 — python: Python: Command-line option injection in webbrowser.open() via crafted URLs
CVE-2026-4786 — python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API
CVE-2026-6100 — python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
🎯 Affected products2
- Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:c60621bae671ef55db3e1f474d78d9ba22109518604dc694d7ef49ef2d240059_amd64 as a component of Red Hat Enterprise Linux AI 3.3
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:10141
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27893
- externalhttps://access.redhat.com/security/cve/CVE-2026-32597
- externalhttps://access.redhat.com/security/cve/CVE-2026-4519
- externalhttps://access.redhat.com/security/cve/CVE-2026-4786
- externalhttps://access.redhat.com/security/cve/CVE-2026-6100
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/technologies/linux-platforms/enterprise-linux/ai
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10141.json