RHSA-2026:59144HighCVSS 7.5

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.4.4 enhancement update

Published
August 24, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-25645 — requests: Requests: Security bypass due to predictable temporary file creation CVE-2026-34753 — vllm: vLLM: Server-Side Request Forgery allows access to internal services via controlled batch input CVE-2026-34755 — vLLM: vLLM: Denial of Service due to excessive video frame processing CVE-2026-34756 — vllm: vLLM: Denial of Service via excessively large 'n' parameter in OpenAI-compatible API CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-44223 — vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding

🎯 Affected products2

  • Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:5489bd1cdbb7f1a5ce80e9ad688b66c6bb8688b2b202a2a86b5c2205cdd6e126_amd64 as a component of Red Hat Enterprise Linux AI 3.4

✅ Remediation

The container disk images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command, for use with OpenShift Virtualization. For details on deploying and configuring RHEL AI, see the Red Hat Enterprise Linux AI documentation at https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.4 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (11)