RHSA-2026:59151HighCVSS 7.5

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.4.4 enhancement update

Published
August 24, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-25645 — requests: Requests: Security bypass due to predictable temporary file creation CVE-2026-34753 — vllm: vLLM: Server-Side Request Forgery allows access to internal services via controlled batch input CVE-2026-34755 — vLLM: vLLM: Denial of Service due to excessive video frame processing CVE-2026-34756 — vllm: vLLM: Denial of Service via excessively large 'n' parameter in OpenAI-compatible API CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-44223 — vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding

🎯 Affected products8

  • Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-aws-cuda-rhel9@sha256:a754d4d1126e98f203249414b3831182bb15ee6b3643452f167849defc642e4b_amd64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-azure-cuda-rhel9@sha256:df5b6edd1bdb055219a7385b6d5923f3262c3a408f92da734e3027af55fd593f_amd64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-azure-rocm-rhel9@sha256:8ea1233b1fb6b82d0aa69e9e4c47d2df242001280c11a61584066c27c5bec3a5_amd64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:a127058368b396a8e8df17dc104469560f40d4451f9135320302568a63380035_arm64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:b45f3bc25a7d3c9f3bfdc1de3be6db59f6c3109f62326d74fae14e832a797981_amd64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-gcp-cuda-rhel9@sha256:bac5d435d156c3ddcb581d3ff05fdce9f72bd617c5b8435cede16bb17b7bf12e_amd64 as a component of Red Hat Enterprise Linux AI 3.4
  • registry.redhat.io/rhelai3/bootc-rocm-rhel9@sha256:38ce057f97034bbb8eaea574d41cc7eebaeaa9265a4cdd966476dd3fac129c3c_amd64 as a component of Red Hat Enterprise Linux AI 3.4

✅ Remediation

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. For details on deploying and configuring RHEL AI, see the Red Hat Enterprise Linux AI documentation at https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.4 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (11)