Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.2.2 (cuda)
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-26740 — giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension CVE-2026-33845 — gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment CVE-2026-33846 — gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly CVE-2026-34982 — vim: arbitrary command execution via modeline sandbox bypass CVE-2026-42009 — gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability CVE-2026-42010 — gnutls: gnutls: Authentication Bypass via NUL Character in Username
🎯 Affected products3
- Red Hat AI Inference Server 3.2
- registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:28c99b2d96643b256e60bd76161d416a83ce0b2c2416ff4b0a2097f956f4a2bc_arm64 as a component of Red Hat AI Inference Server 3.2
- registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:3ae4e369286f3cabc844fc3c37155b89bbe6d34e1a37d93559f0e221e911e197_amd64 as a component of Red Hat AI Inference Server 3.2
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:36004 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file: ~~~ set nomodeline ~~~
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:36004
- externalhttps://access.redhat.com/security/cve/CVE-2026-26740
- externalhttps://access.redhat.com/security/cve/CVE-2026-33845
- externalhttps://access.redhat.com/security/cve/CVE-2026-33846
- externalhttps://access.redhat.com/security/cve/CVE-2026-34982
- externalhttps://access.redhat.com/security/cve/CVE-2026-42009
- externalhttps://access.redhat.com/security/cve/CVE-2026-42010
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai/inference-server
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36004.json