The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- rhaii/model-opt-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-gaudi-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-neuron-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/model-opt-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- Summary
- A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
