RHSA-2026:17609HighCVSS 7.5

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.3

Published
May 14, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing

🎯 Affected products2

  • Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:8fae13d7c13310e2ee707aea7f77c46c6268c0fbec22a00fef4201f8e2caec5d_amd64 as a component of Red Hat Enterprise Linux AI 3.3

✅ Remediation

Before applying this update, ensure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)