The vendor explicitly identifies these products as affected by this CVE.
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- rhaiis-preview/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhelai1/bootc-amd-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-aws-nvidia-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-azure-amd-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- Summary
- A flaw was found in the Hugging Face Transformers library. The convert_config function fails to validate a user-supplied string before using it to execute Python code. An attacker can exploit this flaw by providing a malicious HuBERT model checkpoint, causing arbitrary code execution in the context of the user converting the file.
- Remediation
- For more information visit https://access.redhat.com/errata/RHSA-2026:30078
