CVE-2025-66506

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

Description

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
11.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-02-27 14:54 UTC
CWE-405

Weakness classes (CWE)

  • CWE-405Class

    Asymmetric Resource Consumption (Amplification)

    The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

    cwe.mitre.org →

Affected operating systems

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / gdaltrusty

  • linux

    ubuntu / gdalxenial

  • linux

    ubuntu / golang-go.cryptobionic

  • linux

    ubuntu / golang-go.cryptofocal

  • linux

    ubuntu / golang-go.cryptojammy

  • linux

    ubuntu / golang-go.cryptonoble

  • linux

    ubuntu / golang-go.cryptoquesting

  • linux

    ubuntu / golang-go.cryptoxenial

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • aiohttp

    aiohttp3.13.3

  • anyscale

    ray2.52.0

  • bitnami

    golang1.24.0

  • bitnami

    sqlite

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • go

    github.com/opencontainers/runc1.0.0-rc3

  • go

    github.com/opencontainers/runc1.3.0-rc.1

  • go

    github.com/opencontainers/runc1.4.0-rc.1

  • go

    github.com/sigstore/fulcio

  • go

    golang.org/x/oauth2

  • google

    protobuf33.4

  • IBM

    AIX7.2

  • IBM

    AIX7.3

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    DevOps Code ClearCase10.0.1.05

  • IBM

    DevOps Code ClearCase11.0.0.05

  • IBM

    DevOps Code ClearCase9.1.0.10

  • IBM

    MQContainer

  • IBM

    MQOperator

  • IBM

    TXSeriesfor multiplatforms

  • IBM

    VIOS3.1

  • IBM

    VIOS4.1

  • IGEL

    OS11.11.100

  • IGEL

    OS12.7.4

References & sources

Linked CVEs

Show 15 more CVEs
IDCVE-2025-66506