RHSA-2026:6762HighCVSS 7.5

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (ROCm)

Published
April 7, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2025-68131 — cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse CVE-2025-69227 — aiohttp: aiohttp: Denial of Service via specially crafted POST request CVE-2025-69228 — aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request CVE-2026-25048 — xgrammar: xgrammar: Denial of Service via multi-level nested syntax CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers CVE-2026-32981 — ray: Ray Dashboard Path Traversal Leading to Local File Disclosure

🎯 Affected products2

  • Red Hat AI Inference Server 3.2
  • registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:3e9fbe1a078889d05d0291ef5cfba07924540609f8315c1c88d0f1a13eca5d45_amd64 as a component of Red Hat AI Inference Server 3.2

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:6762 Workaround: To mitigate this issue, applications utilizing the `cbor2` library should avoid reusing `CBORDecoder` instances when processing data from different trust levels. If `CBORDecoder` reuse is unavoidable, ensure that sensitive data is not processed by a decoder instance that will subsequently handle untrusted input. This operational control prevents an attacker from accessing prior decoded information. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (10)