CVE-2026-48586
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)
Beschreibung
Ungenaue Behandlung von stark komprimierten Daten (Datenvergrößerung) Schwachstelle in Apache Thrift C++, Java, Python, Go, D, C/GLib Bindungen. Dieses Problem betrifft Apache Thrift: vor Version 0.24.0. Benutzer werden empfohlen, auf Version 0.24.0 zu aktualisieren, die das Problem behebt.
Metriken
Weakness-Klassen (CWE)
CWE-409Base
Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-07-27 19:49 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CPE Configuration: OR *cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* versions up to (excluding) 0.24.0
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9 Types: Release Notes
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq Types: Vendor Advisory
- CVE Modified2026-07-27 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-48586","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
Betroffene Betriebssysteme
linux
debian / aomtrixie
linux
ubuntu / ffmpegbionic
linux
ubuntu / ffmpegfocal
linux
ubuntu / ffmpegjammy
linux
ubuntu / ffmpegnoble
linux
ubuntu / ffmpegxenial
linux
debian / starlettetrixie
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
anyscale
ray2.52.0
bitnami
pillow8.2.0
bitnami
pillow
bitnami
sqlite
bitnami
thrift
google
protobuf33.4
IBM
Concert< 3.0.0
gefixt in 3.0.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
maven
com.fasterxml.jackson.core:jackson-databind2.10.0
maven
com.fasterxml.jackson.core:jackson-databind2.10.0.pr1
maven
com.fasterxml.jackson.core:jackson-databind2.10.0.pr2
maven
com.fasterxml.jackson.core:jackson-databind2.10.0.pr3
maven
com.fasterxml.jackson.core:jackson-databind2.10.1
maven
com.fasterxml.jackson.core:jackson-databind2.10.2
maven
com.fasterxml.jackson.core:jackson-databind2.10.3
maven
com.fasterxml.jackson.core:jackson-databind2.10.4
maven
com.fasterxml.jackson.core:jackson-databind2.10.5
maven
com.fasterxml.jackson.core:jackson-databind2.10.5.1
maven
com.fasterxml.jackson.core:jackson-databind2.11.0
maven
com.fasterxml.jackson.core:jackson-databind2.11.0.rc1
maven
com.fasterxml.jackson.core:jackson-databind2.11.1
maven
com.fasterxml.jackson.core:jackson-databind2.11.2
maven
com.fasterxml.jackson.core:jackson-databind2.11.3
maven
com.fasterxml.jackson.core:jackson-databind2.11.4
Quellen & Referenzen
- https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prmadvisory
- https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557fix
- https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6dfix
- https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58fix
- https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6fix
- https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651ffix
- https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544fix
- https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572dbfix
- https://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322fix
- https://github.com/opencontainers/runc/commit/b3dd1bc562ed9996d1a0f249e056c16624046d28fix
- https://github.com/opencontainers/runc/commit/d40b3439a9614a86e87b81a94c6811ec6fa2d7d2fix
- https://github.com/opencontainers/runc/commit/d61fd29d854b416feaaf128bf650325cd2182165fix
- https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64fix
- https://github.com/opencontainers/runc/commit/ed6b1693b8b3ae7eb0250a7e76fc888cdacf98c1fix
- https://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3fix
- https://github.com/opencontainers/runc/commit/ff6fe1324663538167eca8b3d3eec61e1bd4fa51fix
- https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480fix
- https://github.com/opencontainers/selinux/pull/237fix
- http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322web
- http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3web
Verknüpfte CVEs
- CVE-2026-64835
FFmpeg-Versionen 4.4 bis 8.1.2 enthalten eine Schwachstelle für den Zugriff auf Speicher außerhalb der Grenzen im ADX-Audiodekodierer inn…
highCVSSv3 8.8 - CVE-2026-64830
FFmpeg-Versionen 2.1 bis 8.1.2 enthalten eine Heap-Buffer-Überlauf-Schwachstelle im VobSub-Untertitel-Demultiplexer, die es Angreifern er…
highCVSSv3 8.8 - CVE-2026-59205
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-59204
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-58049
Der RASC-Videodekodierer von FFmpeg (decode_dlta in libavcodec/rasc.c) führt 32-Bit-Lese- und Schreibvorgänge am Zeilenzeiger durch, bevo…
highCVSSv3 8.6 - CVE-2026-57516
Ray vor Version 2.56.0 enthält eine unsichere Deserialisierungs-Schwachstelle im WebDataset-Leser, die es Angreifern ermöglicht, einen Fe…
highCVSSv3 8.8 - CVE-2026-56211
Ein Ferncodeausführungsfehler wurde in libaom, der Referenzimplementierung des AV1-Codierers, gefunden.
highCVSSv3 7.1 - CVE-2026-56210
Ein Heap-Überlauf-Lese-Schwachstellen wurde in libaom, der Referenz-AV1-Codierungs-Implementierung gefunden.
highCVSSv3 7.1 - CVE-2026-56209
In der Referenzimplementierung des AV1-Codecs libaom wurde eine Schwachstelle für das Schreiben in beliebige Adressen gefunden.
highCVSSv3 7.1 - CVE-2026-56208
Ein Pufferüberlauf im Heap wurde in libaom, der Referenzimplementierung des AV1-Codierers, gefunden.
highCVSSv3 7.6 - CVE-2026-55969
Überlauf oder Umkreisung von Ganzzahlen in den C++, c_glib, Go, netstd, Delphi und Haxe Bindings von Apache Thrift.
highCVSSv3 7.5 - CVE-2026-55574
vLLM ist ein hochdurchsatzfähiger und speichereffizienter Inferenz- und Bereitstellungsmotor für LLMs.
highCVSSv3 7.5 - CVE-2026-55380
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-55379
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-54512
jackson-databind enthält die allgemeine Zweck-Datenbindungsfunktionalität und Baumstruktur für den Jackson Data Processor.
highCVSSv3 8.1 - CVE-2026-54399
Sicherheitslücke durch unkontrollierte Ressourcenverbrauch in dem HTTP/1.1 Nachrichtenparser im Apache HttpComponents Core (Version 5.4.2…
highCVSSv3 7.5 - CVE-2026-54283
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
highCVSSv3 7.5 - CVE-2026-54235
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
mediumCVSSv3 6.5 - CVE-2026-54234
vLLM ist ein hochdurchsatzfähiger und speichereffizienter Inferenz- und Bereitstellungsmotor für LLMs.
highCVSSv3 7.5 - CVE-2026-54060
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-50193
jackson-databind enthält die allgemeine Zweck-Datenbindungsfunktionalität und Baummodell für den Jackson Data Processor.
medium - CVE-2026-48746
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
criticalCVSSv3 9.1 - CVE-2026-44222
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
mediumCVSSv3 6.5 - CVE-2026-41523
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
highCVSSv3 7.5
7 weitere CVEs anzeigen
- CVE-2026-40192
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-11824
SQLite vor Version 3.53.2 enthält eine Schwachstelle durch einen Heap-basierten Pufferüberlauf im FTS5-Full-Text-Sucherweiterung, die es…
highCVSSv3 7.8 - CVE-2026-11822
SQLite vor Version 3.53.2 enthält Sicherheitslücken bezüglich Speicherkorruption in der Erweiterung für die Volltextsuche FTS5.
highCVSSv3 7.8 - CVE-2026-0994
Ein Denial-of-Service-Schwachstellen (DoS) besteht in `google.protobuf.json_format.ParseDict()` in Python, wo die maximale Rekursions-Tie…
highCVSSv3 7.5 - CVE-2025-66418
urllib3 ist eine benutzerfreundliche HTTP-Client-Bibliothek für Python.
high - CVE-2025-62593Aktiv ausgenutzt
Ray ist ein AI-Berechnungsmotor.
criticalCVSSv3 8.8 - CVE-2025-52881
runc ist ein Befehlszeilentool zum Starten und Ausführen von Containern gemäß der OCI-Spezifikation.
high