The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:3019f93c5fb0e513bd701599a90917ce6f590eaf0f43a1fdf40511905bd61833_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:7da55c15dc59a26873e29f8b85550d24ee454d0e453aa08be7660efbcbb6c72a_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:a443c0830f20172529e64227fb217270f0657ecaa85355e1e78b7b42041ad1cb_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:aca243fe44cb3f07c1b64d9c4c52c7261199b47c34c6e28e7b7a39bcc0b2d54a_s390x as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:159c598a60a7dc3a171e023fdb5d5e1e8e698ead21a477da14c5b8e0391bf53d_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:83c1ad7911c900905fd7f15ed1e43d5daf7e46a3134825b45fea2ca636aab93f_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:c1126b6cdaad68b9ec92ea16c056119b8fdcad00c796465a19cb8cc971139bcd_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:dd945b07a139578fba52a5edebd3073f30bed9b36dc7837b736f9ed33c365330_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:1a5ca89ba55b2135f92c885fb70745743e5f6e0dbc592989da20a3243378ab2f_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:3c33d0af817074e1b5e0283b3795e9fc8ae7462511b5e6e696301c23ac2fc524_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:401136911bf9ec14d4123f6dca2813a2cb67281ece7ee25ca825431725d19425_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-trustyai-service-operator-rhel9@sha256:79dbabf88daf5d0cc9f210e77c69a2615ac60b9bc5ccc264d8c60027124564c5_arm64 as a component of Red Hat OpenShift AI 3.4
- Summary
- A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
- Remediation
- For Red Hat OpenShift AI 2.25.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
