RHSA-2026:46956HighCVSS 7.3

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.5

Published
July 27, 2026
Last Modified
August 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API

🎯 Affected products2

  • Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:6d71c4c0d5afba08b44378c833d6d330191383c62f70f428e8984a033c714988_amd64 as a component of Red Hat Enterprise Linux AI 3.3

✅ Remediation

The container disk images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command, for use with OpenShift Virtualization. For details on deploying and configuring RHEL AI, see the Red Hat Enterprise Linux AI documentation at https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.3 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (7)