The vendor explicitly identifies these products as affected by this CVE.
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- rhaiis-preview/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/model-opt-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhelai1/bootc-amd-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-aws-nvidia-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- Summary
- A flaw was found in the Hugging Face Transformers library. The parsing of checkpoints fails to validate user-supplied data, causing a deserialization of untrusted data. An attacker can exploit this issue by providing a malicious X-CLIP model, resulting in arbitrary code execution in the context of the current process processing the file.
- Remediation
- For Red Hat OpenShift AI 2.25.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
