RHSA-2026:76041HighCVSS 9.1

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.7 security update

Published
October 5, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (19)

📋 Description

CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 CVE-2026-41607 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56208 — libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode CVE-2026-56209 — libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack CVE-2026-56210 — libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id CVE-2026-56211 — libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames CVE-2026-57516 — ray: Ray: Remote code execution via unsafe deserialization in WebDataset reader CVE-2026-58049 — FFmpeg: FFmpeg: Memory corruption via crafted RASC video stream CVE-2026-58659 — pytorch-lightning: PyTorch Lightning: Remote code execution via malicious checkpoint files CVE-2026-59888 — com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-73556 — vllm: vLLM: Denial of Service via Regular Expression processing

🎯 Affected products8

  • Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-aws-cuda-rhel9@sha256:1ce4641d373d8f5a2fc7e7f6e8685f24f1f425f5c2545ce83643f02cdf6f46e9_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-azure-cuda-rhel9@sha256:025c44320f25c1e54e5541db02bd16a63954e69695c8543e26e027fe526a1675_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-azure-rocm-rhel9@sha256:5adc2b3523d917b05469e78bebe9b0b3d982848035b81feafeaa5bd090efa2bd_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:dab7d688c3129369cde990766faea337b8e607cfdf7a5c989c3d63ee18e2601d_arm64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:dac2677de5170d1a303983b0e1333b377a82336b59c1e0b82d2e4494641b4303_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-gcp-cuda-rhel9@sha256:16c9d4a6cc45ef4563c27b6d9a86c7d9b34c1f12535aefc1ac89c0ecf78c73fd_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-rocm-rhel9@sha256:dbb413543afce0ffd79b9b7cce64becbab8022db94663b4e16b60871c9c724eb_amd64 as a component of Red Hat Enterprise Linux AI 3.3

✅ Remediation

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. For details on deploying and configuring RHEL AI, see the Red Hat Enterprise Linux AI documentation at https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.3 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library, avoid setting g_lag_in_frames to values >= 1 when processing untrusted input, or validate all encoder configuration parameters before passing them to the libaom API. 2. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 3. For standalone libaom deployments (RHEL-AI, Hummingbird), restrict access to the encoding service to trusted clients only. 4. Apply network-level access controls to limit who can submit video for encoding. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id and temporal_layer_id values are within the configured range [0, configured_layers) before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. Do not expose libaom SVC encoder configuration to untrusted input. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Deploy encoding services with ASLR, stack canaries, and other exploit mitigation technologies enabled. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id does not exceed the number of configured spatial layers before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Monitor encoding service processes for unexpected crashes (segfaults) that may indicate exploitation attempts. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder in a fork-based service, validate all SVC layer parameters (spatial_layer_id, temporal_layer_id) against configured bounds before passing them to the encoder API. 2. Avoid fork-based architectures for encoding services that accept untrusted input. Use thread-based or container-isolated workers instead, which prevent crash oracle attacks. 3. Restrict access to encoding services to trusted clients only. Do not expose SVC encoder configuration or frame submission to untrusted network input. 4. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 5. Enable all available exploit mitigations (ASLR, PIE, stack canaries, CFI) on encoding service binaries. Workaround: To mitigate this issue, restrict the processing of untrusted tar archives by the Ray WebDataset reader. Ensure that only verified and trusted data sources are supplied to the `read_webdataset()` function. Implement strict access controls and input validation for data ingestion pipelines that interact with Ray's WebDataset reader to prevent the introduction of malicious archives. Workaround: Upgrade com.fasterxml.jackson.core:jackson-core to a fixed version, such as 2.18.8 or later, 2.21.4 or later, or the first fixed release in the applicable 2.22.x stream. For Jackson 3.x, upgrade to 3.1.4 or later, or the first fixed release in the applicable 3.2.x stream. If upgrading is not immediately possible, do not expose the non-blocking parser to untrusted, incrementally streamed JSON. Where feasible, use a synchronous parser or buffer and enforce strict request-size, connection-timeout, and concurrency limits at the ingress layer. Apply the upgrade as soon as possible because ingress limits reduce exposure but do not correct the parser defect.

🔗 References (24)