The vendor explicitly identifies these products as affected by this CVE.
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- rhaiis-preview/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhelai1/bootc-amd-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-aws-nvidia-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-azure-amd-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI)
- Summary
- A flaw was found in the Hugging Face Transformers library. The parsing of weights fails to validate user-supplied data, causing a deserialization of untrusted data. An attacker can exploit this issue by providing a malicious GLM4 model, resulting in arbitrary code execution in the context of the current user processing the file.
- Remediation
- For more information visit https://access.redhat.com/errata/RHSA-2026:30078
