RHSA-2026:17611HighCVSS 7.5
Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.3
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
🎯 Affected products8
- Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-aws-cuda-rhel9@sha256:fe3f9992abba61ac90a59107f6f37877876f7cc53378a9712eafb6ebb8a23ded_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-azure-cuda-rhel9@sha256:20f1fe37363bad77ad79184fcd87a1e0b1789d97098726f9b1f9012a90e06929_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-azure-rocm-rhel9@sha256:a5256e0394dbb29e2757969d0a4cacbd1205f3e09bb668d40800133599d75121_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:0e0e0f327f586006f1333353184ebddccb91f1e4dc6ab0d3b96ce2e0e065808e_arm64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:f6f6aa6af83e4005c230be33d0ee66d1826c48bd8e1445049a1550b01a00e703_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-gcp-cuda-rhel9@sha256:3c547595d6b8170a6858ac6b922dc594613c350c9cfa37e83425c247fb795989_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-rocm-rhel9@sha256:d32e15099dad41250e88b8b5030ce34015e084edbf32b06bc00cf97cf30663cb_amd64 as a component of Red Hat Enterprise Linux AI 3.3
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:17611
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-40192
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/technologies/linux-platforms/enterprise-linux/ai
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17611.json