The vendor explicitly identifies these products as affected by this CVE.
- rhoai/odh-modelmesh-runtime-adapter-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in the Keras deep learning library. This vulnerability allows a remote attacker to execute arbitrary code on the system by exploiting improper handling of deserialization in the `Lambda` layer. Specifically, a security safeguard designed to prevent unsafe deserialization is bypassed when the `safe_mode` setting is not explicitly enabled, allowing malicious code to be processed. This can lead to complete compromise of the affected server or user process.
- Remediation
- For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
