Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in RHOAI
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in RHOAI
ID: RHSA-2025:3368
Distribution: Red Hat
Plattformen: Red Hat OpenShift AI 2.16
Datum: Fr, 28. März 2025, 06:33
Referenzen: https://access.redhat.com/errata/RHSA-2025:3368
https://access.redhat.com/security/cve/CVE-2024-56201
https://access.redhat.com/security/cve/CVE-2025-24928
https://access.redhat.com/security/cve/CVE-2024-45339
https://access.redhat.com/security/cve/CVE-2024-55565
https://access.redhat.com/security/cve/CVE-2024-21538
https://access.redhat.com/security/cve/CVE-2024-45296
https://access.redhat.com/security/cve/CVE-2025-22150
https://access.redhat.com/security/cve/CVE-2024-52798
https://access.redhat.com/security/cve/CVE-2025-26791
https://access.redhat.com/security/cve/CVE-2024-45338
https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
https://access.redhat.com/security/cve/CVE-2024-56171
Applikationen: RHOAI

Originalnachricht

Updated images are now available for Red Hat OpenShift AI.

Release of RHOAI 2.16.0 provides these changes:

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2024-21538: Inefficient Regular Expression Complexity (CWE-1333)
CVE-2024-45296: Inefficient Regular Expression Complexity (CWE-1333)
CVE-2024-45338: Allocation of Resources Without Limits or Throttling (CWE-770)
CVE-2024-45339: Improper Link Resolution Before File Access ('Link
Following') (CWE-59)
CVE-2024-52798: Inefficient Regular Expression Complexity (CWE-1333)
CVE-2024-55565: Loop with Unreachable Exit Condition ('Infinite Loop')
(CWE-835)
CVE-2024-56171: Use After Free (CWE-416)
CVE-2024-56201: Improper Neutralization of Escape, Meta, or Control Sequences
(CWE-150)
CVE-2025-22150: Use of Insufficiently Random Values (CWE-330)
CVE-2025-24928: Stack-based Buffer Overflow (CWE-121)
CVE-2025-26791: Improper Neutralization of Input During Web Page Generation
('Cross-site Scripting') (CWE-79)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung