The vendor explicitly identifies these products as affected by this CVE.
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-rhel9 as a component of Lightspeed Core
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- ansible-automation-platform-24/de-supported-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-25/de-minimal-rhel9 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-26/ee-minimal-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in NLTK (Natural Language Toolkit), specifically in the `nltk.app.wordnet_app` component. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted GET request to the local WordNet Browser HTTP server when it is running in its default configuration. This action causes the server process to terminate immediately, leading to a denial of service.
- Remediation
- For Red Hat OpenShift AI 2.25.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
