Red Hat Security Advisory: Red Hat AI Base Images 3.3.4 (Neuron)
🔗 CVE IDs covered (19)
📋 Description
CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c CVE-2026-47162 — vim: Vim: Arbitrary Code Execution via crafted directory names CVE-2026-47167 — vim: Vim: Arbitrary code execution via crafted step-definition patterns CVE-2026-52858 — vim: Vim: Arbitrary code execution via Python omni-completion CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions CVE-2026-55693 — vim: Vim: Out-of-bounds Write in Spell File Word Count CVE-2026-57455 — vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() CVE-2026-57456 — vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion CVE-2026-59856 — vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion CVE-2026-59858 — vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion CVE-2026-64830 — ffmpeg: FFmpeg: Arbitrary code execution via heap buffer overflow in VobSub subtitle demuxer. CVE-2026-73066 — tesseract: Tesseract: Heap out-of-bounds write via crafted .traineddata CVE-2026-73072 — vim: Vim: Heap buffer overflow allows arbitrary code execution CVE-2026-73076 — vim: Vim: Arbitrary command execution via crafted vimball CVE-2026-73077 — vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling CVE-2026-73078 — vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries
🎯 Affected products2
- Red Hat OpenShift AI 3.3
- registry.redhat.io/rhai/base-image-neuron-rhel9@sha256:1b08a53ea84fced411194e15c5ac3dcf6148cfb829ff8e0590cca15988f983cd_amd64 as a component of Red Hat OpenShift AI 3.3
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:74450 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: To mitigate this issue, users should exercise caution when opening untrusted files or repositories with Vim, particularly those that might trigger the `cucumber` filetype plugin. Avoiding interaction with untrusted content can prevent the execution of malicious step-definition patterns. Workaround: Users can mitigate this vulnerability by disabling Python omni-completion in Vim if it is not essential for their workflow. This prevents the execution of untrusted Python code when opening hostile files. To disable this feature, ensure that the `omnifunc` option in your Vim configuration (e.g., `~/.vimrc`) is not set to `pythoncomplete#Complete` or `python3complete#Complete`. Alternatively, users should avoid invoking omni-completion (`Ctrl-X Ctrl-O`) on Python files from untrusted sources. Disabling Python omni-completion may affect Python development functionality within Vim. Workaround: Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory. Workaround: To mitigate this issue disable spell checking or avoid using SOFO-based spell files. This can be achieved globally by adding set nospell to your ~/.vimrc configuration file. Ensure your systems utilize standard UTF-8 encoding. This flaw is strictly confined to legacy 8-bit encodings and cannot be triggered under default Red Hat configurations. Workaround: To mitigate this vulnerability, users should avoid opening untrusted Python files or using Python omni-completion on such files. If Python omni-completion is not required, it can be disabled by adding `autocmd FileType python setlocal omnifunc=` to your `.vimrc` file. This will prevent the vulnerable code from being executed. Disabling Python omni-completion will remove the ability to use `Ctrl-X Ctrl-O` for Python code completion. A restart of Vim is required for the changes to take effect. Workaround: Users should exercise caution when opening untrusted PHP files and avoid invoking omni-completion on them. To prevent exploitation, the PHP omni-completion script can be disabled by moving or renaming `phpcomplete.vim`. For example, execute `mv /usr/share/vim/vim*/autoload/phpcomplete.vim /usr/share/vim/vim*/autoload/phpcomplete.vim.bak`. This action will disable PHP omni-completion functionality. A restart of Vim is necessary for this change to take effect. Workaround: Users are advised to avoid opening untrusted C source files or project tags files in Vim. Exercising caution and only processing trusted content prevents exploitation. Workaround: To mitigate this issue, avoid processing VobSub subtitle files from untrusted or unknown sources. For applications that utilize FFmpeg's VobSub demuxer, consider running them within a sandboxed environment to restrict the potential impact of a successful exploit. Workaround: To mitigate this issue, avoid processing `.traineddata` files from untrusted sources with Tesseract. Ensure that only `.traineddata` files from known, reputable origins are used for OCR recognition. Workaround: If spell checking is unused, disable it with set nospell in ~/.vimrc and do not set spelllang. If spell is required, load only trusted .spl files from Vim’s spell directories and do not place untrusted spell files on runtimepath. Additionally, consider disabling modelines (set nomodeline in ~/.vimrc) to prevent untrusted text files from automatically overriding these settings when opened. Workaround: Avoid installing or removing vimballs from untrusted sources. This vulnerability relies on a user processing a malicious vimball, which then injects commands that are executed during a subsequent vimball operation. Exercise caution when handling vimball files from unknown or unverified origins. Workaround: To mitigate this vulnerability, users can disable the `keywordprg` option for shell script filetypes. This prevents Vim from executing external commands via the `K` command with potentially untrusted input. Create or edit the following files in your Vim configuration directory: - `~/.vim/after/ftplugin/sh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/zsh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/ps1.vim`: `setlocal keywordprg=` This change takes effect the next time a shell script is opened in Vim. Workaround: To mitigate this issue, avoid browsing or bookmarking untrusted or maliciously crafted directory paths within GUI Vim. Users should exercise caution when interacting with `netrw` menu entries derived from external or untrusted sources.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2026:74450
- externalhttps://access.redhat.com/security/cve/CVE-2025-6170
- externalhttps://access.redhat.com/security/cve/CVE-2026-11822
- externalhttps://access.redhat.com/security/cve/CVE-2026-11824
- externalhttps://access.redhat.com/security/cve/CVE-2026-16118
- externalhttps://access.redhat.com/security/cve/CVE-2026-47162
- externalhttps://access.redhat.com/security/cve/CVE-2026-47167
- externalhttps://access.redhat.com/security/cve/CVE-2026-52858
- externalhttps://access.redhat.com/security/cve/CVE-2026-54369
- externalhttps://access.redhat.com/security/cve/CVE-2026-55693
- externalhttps://access.redhat.com/security/cve/CVE-2026-57455
- externalhttps://access.redhat.com/security/cve/CVE-2026-57456
- externalhttps://access.redhat.com/security/cve/CVE-2026-59856
- externalhttps://access.redhat.com/security/cve/CVE-2026-59858
- externalhttps://access.redhat.com/security/cve/CVE-2026-64830
- externalhttps://access.redhat.com/security/cve/CVE-2026-73066
- externalhttps://access.redhat.com/security/cve/CVE-2026-73072
- externalhttps://access.redhat.com/security/cve/CVE-2026-73076
- externalhttps://access.redhat.com/security/cve/CVE-2026-73077
- externalhttps://access.redhat.com/security/cve/CVE-2026-73078
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74450.json