Red Hat Security Advisory: Red Hat AI Inference Server 3.2.5 (ROCm)
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh CVE-2025-47906 — os/exec: Unexpected paths returned from LookPath in os/exec CVE-2025-52565 — runc: container escape with malicious config due to /dev/console mount and related races CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing CVE-2025-62164 — vllm: VLLM deserialization vulnerability leading to DoS and potential RCE CVE-2025-62372 — vllm: vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs CVE-2025-66448 — vllm: vLLM: Remote Code Execution via malicious model configuration CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:23449
- externalhttps://access.redhat.com/security/cve/CVE-2025-22868
- externalhttps://access.redhat.com/security/cve/CVE-2025-22869
- externalhttps://access.redhat.com/security/cve/CVE-2025-47906
- externalhttps://access.redhat.com/security/cve/CVE-2025-52565
- externalhttps://access.redhat.com/security/cve/CVE-2025-59375
- externalhttps://access.redhat.com/security/cve/CVE-2025-62164
- externalhttps://access.redhat.com/security/cve/CVE-2025-62372
- externalhttps://access.redhat.com/security/cve/CVE-2025-66448
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2025-9230
- externalhttps://access.redhat.com/security/cve/CVE-2025-9714
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai/inference-server
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23449.json