RHSA-2026:49715HighCVSS 8.4
Red Hat Security Advisory: RHEL AI 3.5 RPM runtime CVE fix - thrift
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-55971 — thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow
🎯 Affected products47
- Red Hat Enterprise Linux AI 3.5 for RHEL 9
- perl-thrift-0:0.24.0-1.el9ai.noarch as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-0:0.24.0-1.el9ai.src as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debuginfo-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debugsource-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debugsource-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debugsource-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-debugsource-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- thrift-devel-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
- +17 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available other than upgrading to Apache Thrift 0.24.0 or later, which contains the fix. AIPCC's PyArrow build pipeline is tracked separately for remediation under AIPCC-28667.