RHSA-2026:71393HighCVSS 8.8

Red Hat Security Advisory: Red Hat AI Base Images 3.5.1 (CPU)

Published
September 24, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56208 — libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode CVE-2026-56209 — libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack CVE-2026-56210 — libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id CVE-2026-56211 — libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files

🎯 Affected products5

  • Red Hat OpenShift AI 3.5
  • registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:49e937f79f8f5af859054f29f307ab9580babe35ae27bddc1e7afef2193e5d6f_amd64 as a component of Red Hat OpenShift AI 3.5
  • registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:5e6b096224b7e72d445194aa07739bb8999c7c3ef241dbefee04ea6548ae0d93_arm64 as a component of Red Hat OpenShift AI 3.5
  • registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:7cbb9db26c677e1a32ea65c7f1ef71657bce6544da2e3fe8df173d30102ec74b_s390x as a component of Red Hat OpenShift AI 3.5
  • registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:9a3a489f8d713128142772724af0cdb12ce25f4f2816f07ca7b9a89b34ae74c1_ppc64le as a component of Red Hat OpenShift AI 3.5

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:71393 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library, avoid setting g_lag_in_frames to values >= 1 when processing untrusted input, or validate all encoder configuration parameters before passing them to the libaom API. 2. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 3. For standalone libaom deployments (RHEL-AI, Hummingbird), restrict access to the encoding service to trusted clients only. 4. Apply network-level access controls to limit who can submit video for encoding. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id and temporal_layer_id values are within the configured range [0, configured_layers) before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. Do not expose libaom SVC encoder configuration to untrusted input. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Deploy encoding services with ASLR, stack canaries, and other exploit mitigation technologies enabled. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id does not exceed the number of configured spatial layers before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Monitor encoding service processes for unexpected crashes (segfaults) that may indicate exploitation attempts. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder in a fork-based service, validate all SVC layer parameters (spatial_layer_id, temporal_layer_id) against configured bounds before passing them to the encoder API. 2. Avoid fork-based architectures for encoding services that accept untrusted input. Use thread-based or container-isolated workers instead, which prevent crash oracle attacks. 3. Restrict access to encoding services to trusted clients only. Do not expose SVC encoder configuration or frame submission to untrusted network input. 4. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 5. Enable all available exploit mitigations (ASLR, PIE, stack canaries, CFI) on encoding service binaries.

🔗 References (12)