CVE-2025-9900
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)
Description
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Metrics
Weakness classes (CWE)
CWE-123Base
Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
cwe.mitre.org →
Affected operating systems
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
ubuntu / gdaltrusty
linux
ubuntu / gdalxenial
linux
ubuntu / golang-go.cryptobionic
linux
ubuntu / golang-go.cryptofocal
linux
ubuntu / golang-go.cryptojammy
linux
ubuntu / golang-go.cryptonoble
linux
ubuntu / golang-go.cryptoquesting
linux
ubuntu / golang-go.cryptoxenial
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
aiohttp
aiohttp3.13.3
anyscale
ray2.52.0
bitnami
golang1.24.0
bitnami
sqlite
Dell
Secure Connect GatewayAppliance 5.32.00.18
go
github.com/opencontainers/runc1.0.0-rc3
go
github.com/opencontainers/runc1.3.0-rc.1
go
github.com/opencontainers/runc1.4.0-rc.1
go
github.com/sigstore/fulcio
go
golang.org/x/oauth2
google
protobuf33.4
IBM
AIX7.2
IBM
AIX7.3
IBM
Concert< 3.0.0
fixed in 3.0.0
IBM
DevOps Code ClearCase10.0.1.05
IBM
DevOps Code ClearCase11.0.0.05
IBM
DevOps Code ClearCase9.1.0.10
IBM
MQContainer
IBM
MQOperator
IBM
TXSeriesfor multiplatforms
IBM
VIOS3.1
IBM
VIOS4.1
IGEL
OS11.11.100
IGEL
OS12.7.4
References & sources
- https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6vweb
- https://nvd.nist.gov/vuln/detail/CVE-2025-62593advisory
- https://github.com/nccgroup/singularity/pull/68web
- https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09web
- https://docs.ray.io/en/releases-2.51.1/ray-security/index.htmlweb
- https://en.wikipedia.org/wiki/Malvertisingweb
- https://github.com/ray-project/raypackage
- https://github.com/ray-project/ray/blob/e7889ae542bf0188610bc8b06d274cbf53790cbd/python/ray/dashboard/http_server_head.py#L184-L196web
- https://github.com/ray-project/ray/blob/f39a860436dca3ed5b9dfae84bd867ac10c84dc6/python/ray/dashboard/optional_utils.py#L129-L155web
- https://pypi.org/project/raypackage
- https://github.com/advisories/GHSA-q279-jhrf-cc6vadvisory
- https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysisthird-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593government-resource
- https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qwweb
- https://nvd.nist.gov/vuln/detail/CVE-2025-62372advisory
- https://github.com/vllm-project/vllm/pull/27204web
- https://github.com/vllm-project/vllm/pull/6613web
- https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84bweb
- https://github.com/advisories/GHSA-pmqf-x6x8-p7qwadvisory
- https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yamlweb
Linked CVEs
- CVE-2026-25990
Pillow is a Python imaging library.
highCVSSv3 7.5 - CVE-2026-24779
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 7.1 - CVE-2026-24486
A flaw was found in Python-Multipart, a tool for parsing multipart form data in Python applications.
highCVSSv3 8.6 - CVE-2026-24049
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427.
highCVSSv3 7.1 - CVE-2026-22807
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 8.8 - CVE-2026-22778
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
criticalCVSSv3 9.8 - CVE-2026-22773
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
mediumCVSSv3 6.5 - CVE-2026-21441
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2026-0994
A flaw was found in protobuf.
highCVSSv3 7.5 - CVE-2025-9714
A flaw was found in libxstl/libxml2.
mediumCVSSv3 6.2 - CVE-2025-9230
A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap).
highCVSSv3 7.5 - CVE-2025-8176
A flaw was found in libtiff.
mediumCVSSv3 5.3 - CVE-2025-6965
A memory corruption flaw was found in SQLite.
high - CVE-2025-69223
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python.
highCVSSv3 7.5 - CVE-2025-66506
A flaw was found in Fulcio, a free-to-use certificate authority.
highCVSSv3 7.5 - CVE-2025-66471
A decompression handling flaw has been discovered in urllib3.
high - CVE-2025-66448
A remote code execution vulnerability has been identified in vLLM.
highCVSSv3 7.1 - CVE-2025-66418
A flaw was found in urllib3 Python library that could lead to a Denial of Service condition.
high - CVE-2025-62727
A denial of service vulnerability has been discovered in the python Starlette framework.
highCVSSv3 7.5 - CVE-2025-62593Actively exploited
A flaw was found in Ray’s HTTP API endpoint handling (e.g.
criticalCVSSv3 8.8 - CVE-2025-62426
A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying craf…
mediumCVSSv3 6.5 - CVE-2025-6242
A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set.
highCVSSv3 7.1 - CVE-2025-62372
A denial-of-service vulnerability in vLLM allows an attacker with API access to crash the engine by submitting multimodal embedding tenso…
high - CVE-2025-62164
A vulnerability in vLLM allows attackers to supply malicious serialized prompt-embedding tensors that are deserialized using torch.load()…
highCVSSv3 8.8
Show 15 more CVEs
- CVE-2025-61620
A flaw was found in the server implementation of vLLM, where the handling of Jinja templates does not properly validate user-supplied inp…
— - CVE-2025-59425
A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time.
highCVSSv3 7.5 - CVE-2025-59375
A memory amplification vulnerability in libexpat allows attackers to trigger excessive dynamic memory allocations by submitting specially…
highCVSSv3 7.5 - CVE-2025-53906
A path traversal flaw was found in Vim.
mediumCVSSv3 4.1 - CVE-2025-53905
A path traversal flaw was found in Vim.
mediumCVSSv3 4.1 - CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2.
mediumCVSSv3 5.4 - CVE-2025-52565
A flaw was found in runc.
high - CVE-2025-47906
A path handling flaw has been discovered in the os/exec go package.
— - CVE-2025-22869
A flaw was found in the golang.org/x/crypto/ssh package.
— - CVE-2025-22868
A flaw was found in the `golang.org/x/oauth2/jws` package in the token parsing component.
— - CVE-2025-15467
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer…
highCVSSv3 8.8 - CVE-2024-56433
A flaw was found in shadow-utils.
lowCVSSv3 3.6 - CVE-2023-52356
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API.
highCVSSv3 7.5 - CVE-2023-52355
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API.
highCVSSv3 7.5 - CVE-2023-48022
A flaw was found in ray.
criticalCVSSv3 9.8