Red Hat Security Advisory: Red Hat AI Inference Server 3.3.6 (ROCm)
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-47155 — vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls CVE-2026-53923 — vllm: vLLM: Information disclosure via integer truncation
🎯 Affected products2
- Red Hat AI Inference Server 3.3
- registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:dbce78adf45d71b4348c55a3aa1dd9327ea7ec726cf0e5487246de180ecf8a3e_amd64 as a component of Red Hat AI Inference Server 3.3
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:59139 Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Upgrade to a vLLM build containing the fix (>= 0.22.0) when available from Red Hat. Until then, only serve models from trusted registries, pin revisions explicitly, and review nested artifacts in model repositories before deployment. Workaround: No mitigation is required for unaffected deployments. Restrict untrusted access to inference APIs as a general hardening measure.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:59139
- externalhttps://access.redhat.com/security/cve/CVE-2026-41523
- externalhttps://access.redhat.com/security/cve/CVE-2026-47155
- externalhttps://access.redhat.com/security/cve/CVE-2026-53923
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai/inference-server
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59139.json