Red Hat Security Advisory: Red Hat OpenShift AI 3.4.0-ea.1 Release
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-22807 — vLLM: vLLM: Arbitrary code execution via untrusted model loading CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
🎯 Affected products200
- Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:222cf5b9b5aae11b94219359cc22809758fab30975bcfcceee99ed6027b2fbb1_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:592a5d44e55480a36981cb026c8c79aa39f805b9c5da3b8f1fb0a1af42be5c30_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:a5f71b9619b7b9513ec9a50e7c4d7447c132fe5c0d99d165d64b0fc47dc9b77f_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e5c6a71391717a03dae43e824e623bdc44212cfe43e2df9d5350a8963ab4785a_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:5ccac21543fa149400526462b5229d8e4cc85aba70b15145cbf0e6a5496708bc_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:b6c7674246bb9677b05dd05170344cb0a16d727cae2a43ebcfc7f8d175bcf92b_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:07d5bf3973ea63ab33a79bab3cebedfc47c8df863155dbb85d26ffb5ce6b512b_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5cc0826b0ff37ec9b51eb81ac0784a6dbf4e849f6b6139aef18ee6d50d772d8e_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:db6c2b19198bdaa5add56776a5947f54810cdbb3b177dabc76b5c4e8ce5cfabb_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:e11115022e0089a56e74cfb1c36b333f73249c0fae158fb7acea7fc2134cbbf7_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:14e8305af3a2bd7f7b967244b614b3ef8ef729bda4ed9fe67512f10703975418_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:25ff15212521f7ab9b9e3183eba74326d69f229c7e75758c519d4a13406c4eeb_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:669466c5f403556927c4538195d46ab638a28fc6a409245a306f1af0bd8eb82a_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:5945da20e9986f58ff9bb6d777b84b6eef7ec7edb929e6e4a4cfe1a28999bd36_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:7f77fdac05ea8a429c529caaee233c9d46b9aee230f543af37ac2ec23be2b5f9_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:84be65372b1b97a1d07d02946ddfc7c653fcb1cb59819cc7ee770a343a49df40_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:008a2605fb6e083bc47e896d83b3294a7455149b33ceeca2e2e375e548a6baa1_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:1b0978e5e6788a48aa5ba4b53fc79c56e1c56d18c5a3fff0adaa87c5cee4a8b4_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:a45e7e35b6d18c7c52c3d72ad56ebea0fe041a68b6b5726b1bea516b7adf1c81_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-eval-hub-rhel9@sha256:2b8810f0135a22f1fdd988e4cf595742de0289be2b7f45aee8bdc139850a288e_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:70226c126b33fb39e221a50cc5eb95963208fea44c12a830f60d2837e7e511a1_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:97e7e848e74dd00f9c4dc47e3d40369e9ce6667bccbf1542a5ba6c7623bfc4b5_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:d1994800072b5f4449f7474436d81c2dfdc606ffd97c7f3c7d068aa93ffb31e8_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:0df9430d50a510ab1a2f906c59187e62f8e52131ea7e93fe4d32a94678e5e5b6_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:13da65e17d4e353b578b59a924566625459f8f8a4d88473bab22d7f7d7284bb0_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:dd76a443b36f977704f7f3c880366c261802e1e4612b52624cf37a1d71a31af0_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:0e38b2d3bead1898c12afc660cec9b2552b410acbd453e3477d04a71b190f9e0_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:1225c6a3ac27b5469a69c7ec53159f90f1ca27a61154c018ea34987adee05fc5_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:74493eaf93afbfe8a5a2e97a0381159fcc18cc7f29342778e564b07886224887_s390x as a component of Red Hat OpenShift AI 3.4
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.4.0-ea.1 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: To mitigate this issue, ensure that vLLM instances are configured to load models only from trusted and verified repositories. Restrict access to the model repository path to prevent unauthorized modification or introduction of malicious code. Implement strict access controls and integrity checks for all model sources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:5119
- externalhttps://access.redhat.com/security/cve/CVE-2026-22807
- externalhttps://access.redhat.com/security/cve/CVE-2026-24049
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5119.json