RHSA-2026:49715HighCVSS 8.4

Red Hat Security Advisory: RHEL AI 3.5 RPM runtime CVE fix - thrift

Published
August 3, 2026
Last Modified
August 3, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-55971 — thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow

🎯 Affected products47

  • Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • perl-thrift-0:0.24.0-1.el9ai.noarch as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • python3-thrift-debuginfo-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-0:0.24.0-1.el9ai.src as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debuginfo-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debugsource-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debugsource-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debugsource-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-debugsource-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • thrift-devel-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.5 for RHEL 9
  • +17 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available other than upgrading to Apache Thrift 0.24.0 or later, which contains the fix. AIPCC's PyArrow build pipeline is tracked separately for remediation under AIPCC-28667.

🔗 References (4)