Red Hat Security Advisory: RHOAI 2.25.1 - Red Hat OpenShift AI
🔗 CVE IDs covered (12)
📋 Description
CVE-2025-9905 — keras: Arbitary Code execution in Keras load_model() CVE-2025-9906 — keras: Arbitrary Code execution in Keras Safe Mode CVE-2025-12060 — keras: Keras Path Traversal Vulnerability CVE-2025-12638 — keras: Path Traversal Vulnerability in keras CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-49655 — keras: Keras deserialization of untrusted data CVE-2025-53643 — aiohttp: AIOHTTP HTTP Request/Response Smuggling CVE-2025-62164 — vllm: VLLM deserialization vulnerability leading to DoS and potential RCE CVE-2025-62593 — ray: Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack CVE-2025-62727 — starlette: Starlette DoS via Range header merging CVE-2025-64756 — glob: glob: Command Injection Vulnerability via Malicious Filenames CVE-2025-66416 — mcp: DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:23531
- externalhttps://access.redhat.com/security/cve/CVE-2025-12060
- externalhttps://access.redhat.com/security/cve/CVE-2025-12638
- externalhttps://access.redhat.com/security/cve/CVE-2025-47913
- externalhttps://access.redhat.com/security/cve/CVE-2025-49655
- externalhttps://access.redhat.com/security/cve/CVE-2025-53643
- externalhttps://access.redhat.com/security/cve/CVE-2025-62164
- externalhttps://access.redhat.com/security/cve/CVE-2025-62593
- externalhttps://access.redhat.com/security/cve/CVE-2025-62727
- externalhttps://access.redhat.com/security/cve/CVE-2025-64756
- externalhttps://access.redhat.com/security/cve/CVE-2025-66416
- externalhttps://access.redhat.com/security/cve/CVE-2025-9905
- externalhttps://access.redhat.com/security/cve/CVE-2025-9906
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23531.json