Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.2.2 (CUDA)
🔗 CVE IDs covered (9)
📋 Description
CVE-2020-23922 — giflib: out-of-bounds read in DumpScreen2RGB() in gif2rgb.c in gif2rgb tool CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32296 — kernel: insufficient TCP source port randomness leads to client identification CVE-2023-6349 — libvpx: Heap buffer overflow related to VP9 encoding CVE-2023-39327 — openjpeg: Malicious files can cause the program to enter a large loop CVE-2023-39329 — openjpeg: Resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c CVE-2024-45341 — golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints CVE-2024-50613 — libsndfile: Reachable assertion in mpeg_l3_encoder_close CVE-2026-25990 — pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
🎯 Affected products3
- Red Hat AI Inference Server 3.2
- registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:2fd4f343235f7e896a70169fc4b856343d639c65bec77c1883cbd8210caf3a92_amd64 as a component of Red Hat AI Inference Server 3.2
- registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:9c1beb862965c37ec54cbc5e5f2352ba83b3f377ce5c2a9909b943081abb55ac_arm64 as a component of Red Hat AI Inference Server 3.2
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:4128 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:4128
- externalhttps://access.redhat.com/security/cve/CVE-2020-23922
- externalhttps://access.redhat.com/security/cve/CVE-2022-32189
- externalhttps://access.redhat.com/security/cve/CVE-2022-32296
- externalhttps://access.redhat.com/security/cve/CVE-2023-39327
- externalhttps://access.redhat.com/security/cve/CVE-2023-39329
- externalhttps://access.redhat.com/security/cve/CVE-2023-6349
- externalhttps://access.redhat.com/security/cve/CVE-2024-45341
- externalhttps://access.redhat.com/security/cve/CVE-2024-50613
- externalhttps://access.redhat.com/security/cve/CVE-2026-25990
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai/inference-server
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4128.json