The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cpu-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cuda-12.9-rhel9 as a component of Lightspeed Core
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-ocp-rag-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ta-lmes-job-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in the `nltk.downloader` component of NLTK. This vulnerability allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces and only validates package integrity after extraction. This design flaw enables one package to overwrite another package's trusted resources, leading to an integrity compromise that can affect machine learning pipelines and reproducibility-sensitive environments.
- Remediation
- Fix deferred
