Red Hat Security Advisory: Red Hat AI Inference 3.4.4 (cuda)
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-34753 — vllm: vLLM: Server-Side Request Forgery allows access to internal services via controlled batch input CVE-2026-34755 — vLLM: vLLM: Denial of Service due to excessive video frame processing CVE-2026-34756 — vllm: vLLM: Denial of Service via excessively large 'n' parameter in OpenAI-compatible API CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-44223 — vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding
🎯 Affected products3
- Red Hat AI Inference Server 3.4
- registry.redhat.io/rhaii/vllm-cuda-rhel9@sha256:5da7a63ad71f6d047a35bfbd572a141be894bae84e60a2b22a237116c477a248_arm64 as a component of Red Hat AI Inference Server 3.4
- registry.redhat.io/rhaii/vllm-cuda-rhel9@sha256:d2ed07d307845135c089bc7644b64734b9349d517abf746c9aa0aa23ed263da5_amd64 as a component of Red Hat AI Inference Server 3.4
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:57389 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:57389
- externalhttps://access.redhat.com/security/cve/CVE-2026-34753
- externalhttps://access.redhat.com/security/cve/CVE-2026-34755
- externalhttps://access.redhat.com/security/cve/CVE-2026-34756
- externalhttps://access.redhat.com/security/cve/CVE-2026-41523
- externalhttps://access.redhat.com/security/cve/CVE-2026-44223
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai/inference-server
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_57389.json