Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.5
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
🎯 Affected products3
- Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:2897dd2e5429b271adbe81fcff8c10f60ce2b441bb9a2d61e36b8db55250a5ae_amd64 as a component of Red Hat Enterprise Linux AI 3.3
- registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:d050d91146b0d4e31176a679e88d1d710e5b39952eadb316b1ee5a49a11bd146_arm64 as a component of Red Hat Enterprise Linux AI 3.3
✅ Remediation
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. For details on deploying and configuring RHEL AI, see the Red Hat Enterprise Linux AI documentation at https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.3 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:43670
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-39892
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.3/html/release_notes/rhelai-33-stable-release-notes_release-notes
- externalhttps://www.redhat.com/en/technologies/linux-platforms/enterprise-linux/ai
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43670.json