CVE-2026-48586

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

Beschreibung

Ungenaue Behandlung von stark komprimierten Daten (Datenvergrößerung) Schwachstelle in Apache Thrift C++, Java, Python, Go, D, C/GLib Bindungen. Dieses Problem betrifft Apache Thrift: vor Version 0.24.0. Benutzer werden empfohlen, auf Version 0.24.0 zu aktualisieren, die das Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.7
Quelle: nvd-v4
48.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-31 13:38 UTC
CWE-409

Weakness-Klassen (CWE)

  • CWE-409Base

    Improper Handling of Highly Compressed Data (Data Amplification)

    The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-27 19:49 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CPE Configuration: OR *cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* versions up to (excluding) 0.24.0
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9 Types: Release Notes
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq Types: Vendor Advisory
  2. CVE Modified2026-07-27 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-48586","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…

Betroffene Betriebssysteme

  • linux

    debian / aomtrixie

  • linux

    ubuntu / ffmpegbionic

  • linux

    ubuntu / ffmpegfocal

  • linux

    ubuntu / ffmpegjammy

  • linux

    ubuntu / ffmpegnoble

  • linux

    ubuntu / ffmpegxenial

  • linux

    debian / starlettetrixie

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • anyscale

    ray2.52.0

  • bitnami

    pillow8.2.0

  • bitnami

    pillow

  • bitnami

    sqlite

  • bitnami

    thrift

  • google

    protobuf33.4

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.4

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.5

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.5.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.0

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.0.rc1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.4

Quellen & Referenzen

Verknüpfte CVEs

7 weitere CVEs anzeigen
IDCVE-2026-48586