VDB
RHSA-2025%3A23209
RHSA-2025%3A23209
PUBLISHED
CVSS 5.599999904632568 MEDIUM
A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI).
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64 as a component of Red Hat AI Inference Server 3.2 | *, *, registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64 |
| Red Hat | registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64 as a component of Red Hat AI Inference Server 3.2 | registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64, registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64, registry.redhat.io/rhaiis/vllm-tpu-rhel9@sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534_amd64 |
| Red Hat | Red Hat AI Inference Server 3.2 |
Timeline
- Dec 15, 2025 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 10, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
References
- https://www.redhat.com/en/products/ai/inference-server advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2348367 issue
- https://www.cve.org/CVERecord?id=CVE-2025-59375 advisory
- https://access.redhat.com/errata/RHSA-2025:23209 advisory
- https://github.com/vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf advisory
- https://access.redhat.com/security/cve/CVE-2025-9714 advisory
- https://access.redhat.com/security/cve/CVE-2025-66448 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2416282 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23209.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395108 issue
- https://github.com/sigstore/fulcio/security/advisories/GHSA-f83f-xpx7-ffpw advisory
- https://access.redhat.com/security/cve/CVE-2025-62372 advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/677a42645ef22b5a50741bad5facf9d8a8bc6d21 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2404708 issue
- https://access.redhat.com/security/cve/CVE-2025-9230 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392605 issue
- https://www.cve.org/CVERecord?id=CVE-2025-22868 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418152 issue
- https://github.com/vllm-project/vllm/commit/ffb08379d8870a1a81ba82b72797f196838d0c86 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9714 advisory
…and 45 more