The vendor explicitly identifies these products as affected by this CVE.
- rhaii/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- rhelai3/bootc-aws-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-azure-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gcp-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-openvino-model-server-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit a bypass in the `trust_remote_code` mechanism within the `DiffusionPipeline.from_pretrained` function. This vulnerability allows for arbitrary remote code execution, even when the user explicitly sets `trust_remote_code=False` or omits it. The issue stems from the security check being incorrectly placed, allowing malicious code to be loaded and executed by bypassing the intended security gate.
- Remediation
- For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
