CVE-2025-6965

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

Beschreibung

Es existiert eine Schwachstelle in SQLite-Versionen vor 3.50.2, bei der die Anzahl der Aggregatbegriffe die Anzahl der verfügbaren Spalten überschreiten kann. Dies könnte zu einem Speicherkorruptionsproblem führen. Wir empfehlen ein Upgrade auf Version 3.50.2 oder höher.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.2
Quelle: nvd-v4
99.5 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
75.8 %
Hoch — Modell schätzt ≥ 50 % Chance auf reale Ausnutzung in 30 Tagen.
Veröffentlicht
2026-02-27 14:54 UTC
CWE-197

Weakness-Klassen (CWE)

  • CWE-197Base

    Numeric Truncation Error

    Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / gdaltrusty

  • linux

    ubuntu / gdalxenial

  • linux

    ubuntu / golang-go.cryptobionic

  • linux

    ubuntu / golang-go.cryptofocal

  • linux

    ubuntu / golang-go.cryptojammy

  • linux

    ubuntu / golang-go.cryptonoble

  • linux

    ubuntu / golang-go.cryptoquesting

  • linux

    ubuntu / golang-go.cryptoxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • aiohttp

    aiohttp3.13.3

  • anyscale

    ray2.52.0

  • bitnami

    golang1.24.0

  • bitnami

    sqlite

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • go

    github.com/opencontainers/runc1.0.0-rc3

  • go

    github.com/opencontainers/runc1.3.0-rc.1

  • go

    github.com/opencontainers/runc1.4.0-rc.1

  • go

    github.com/sigstore/fulcio

  • go

    golang.org/x/oauth2

  • google

    protobuf33.4

  • IBM

    AIX7.2

  • IBM

    AIX7.3

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • IBM

    DevOps Code ClearCase10.0.1.05

  • IBM

    DevOps Code ClearCase11.0.0.05

  • IBM

    DevOps Code ClearCase9.1.0.10

  • IBM

    MQContainer

  • IBM

    MQOperator

  • IBM

    TXSeriesfor multiplatforms

  • IBM

    VIOS3.1

  • IBM

    VIOS4.1

  • IGEL

    OS11.11.100

  • IGEL

    OS12.7.4

Quellen & Referenzen

Verknüpfte CVEs

15 weitere CVEs anzeigen
IDCVE-2025-6965