Red Hat Security Advisory: Red Hat AI Inference Server 3.0 (ROCm)
Red Hat® AI Inference Server
AI Analysis
Technical Summary
CVE-2025-47277 affects Red Hat AI Inference Server 3.0 (vLLM) and involves a deserialization flaw in the PyNcclPipe KV cache transfer interface used with the V0 engine. This flaw allows an attacker with network access to the TCPStore interface to perform unauthorized access to key-value caches and potentially achieve remote code execution by exploiting unsafe deserialization (CWE-502). The vulnerability is mitigated by default network isolation of vLLM nodes, and the vulnerable interface is not intended for exposure outside secured internal clusters. Exploitation requires a misconfiguration that exposes the TCPStore service to untrusted networks. Red Hat classifies this vulnerability as moderate due to limited exploitability and impact scope. No patch or mitigation meeting Red Hat's standards is currently available, and users are advised to maintain proper network segmentation and follow documented deployment guidelines.
Potential Impact
The vulnerability could allow an attacker with direct network access to a misconfigured or publicly exposed TCPStore interface to execute arbitrary code remotely via unsafe deserialization. This impacts confidentiality, integrity, and availability of the affected system. However, the risk is constrained by the requirement for specific deployment conditions: the use of the V0 engine with PyNcclPipe, and exposure of the TCPStore service outside isolated internal networks. Under default configurations, the vulnerability is not exploitable. There are no known exploits in the wild. The overall impact is rated moderate by Red Hat.
Mitigation Recommendations
Red Hat currently does not provide a patch or mitigation that meets their standards for usability and stability. The vulnerability is mitigated by default network isolation of vLLM nodes, and the TCPStore interface should not be exposed to untrusted networks. Users should ensure that vLLM deployments follow the official documentation to restrict network exposure and avoid binding the TCPStore service to public interfaces. Monitoring and maintaining proper network segmentation is recommended until an official fix is released.
Red Hat Security Advisory: Red Hat AI Inference Server 3.0 (ROCm)
Description
Red Hat® AI Inference Server
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-47277 affects Red Hat AI Inference Server 3.0 (vLLM) and involves a deserialization flaw in the PyNcclPipe KV cache transfer interface used with the V0 engine. This flaw allows an attacker with network access to the TCPStore interface to perform unauthorized access to key-value caches and potentially achieve remote code execution by exploiting unsafe deserialization (CWE-502). The vulnerability is mitigated by default network isolation of vLLM nodes, and the vulnerable interface is not intended for exposure outside secured internal clusters. Exploitation requires a misconfiguration that exposes the TCPStore service to untrusted networks. Red Hat classifies this vulnerability as moderate due to limited exploitability and impact scope. No patch or mitigation meeting Red Hat's standards is currently available, and users are advised to maintain proper network segmentation and follow documented deployment guidelines.
Potential Impact
The vulnerability could allow an attacker with direct network access to a misconfigured or publicly exposed TCPStore interface to execute arbitrary code remotely via unsafe deserialization. This impacts confidentiality, integrity, and availability of the affected system. However, the risk is constrained by the requirement for specific deployment conditions: the use of the V0 engine with PyNcclPipe, and exposure of the TCPStore service outside isolated internal networks. Under default configurations, the vulnerability is not exploitable. There are no known exploits in the wild. The overall impact is rated moderate by Red Hat.
Mitigation Recommendations
Red Hat currently does not provide a patch or mitigation that meets their standards for usability and stability. The vulnerability is mitigated by default network isolation of vLLM nodes, and the TCPStore interface should not be exposed to untrusted networks. Users should ensure that vLLM deployments follow the official documentation to restrict network exposure and avoid binding the TCPStore service to public interfaces. Monitoring and maintaining proper network segmentation is recommended until an official fix is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:10404
- Cve Count
- 1
Threat ID: 6a4049d327e9c7971982c5af
Added to database: 06/27/2026, 22:08:19 UTC
Last enriched: 08/16/2026, 18:18:28 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.