Skip to main content
EPSS 1.6%top 26%

Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.2.5 (CUDA)

0
High
Published: 12/15/2025 (12/15/2025, 15:29:01 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat® AI Inference Server Model Optimization Tools

Affected software

Affected versions
=3.2.5Red HatRed Hat AI Inference ServerRed Hat AI Inference Server 3.2amd64registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:19:22 UTC

Technical Analysis

This advisory covers multiple vulnerabilities affecting Red Hat AI Inference Server Model Optimization Tools 3.2.5 (CUDA), including CVE-2025-9230 and six additional CVEs. Among these, CVE-2025-22868 is a flaw in the golang.org/x/oauth2/jws package where token parsing uses strings.Split(token, "."), allowing an attacker to craft tokens with excessive '.' characters that cause high memory consumption and denial of service. The vulnerabilities are associated with several CWEs such as CWE-787 (out-of-bounds write), CWE-606 (unverified input in loop condition), CWE-1286 (improper validation of syntactic correctness), CWE-770 (allocation of resources without limits), CWE-59 (link following), and CWE-405 (missing initialization). Red Hat has not yet released patches or fixes for these issues. The vendor advisory recommends mitigation by pre-validating tokens to avoid excessive '.' characters. No active exploitation is known, and the vulnerabilities affect the exact version 3.2.5 of the product. The product is not cloud-hosted, so remediation depends on patch availability.

Potential Impact

The primary impact is potential denial of service due to memory exhaustion when processing maliciously crafted tokens with excessive '.' characters. This can disrupt availability of the Red Hat AI Inference Server Model Optimization Tools 3.2.5 (CUDA). No confidentiality or integrity impacts are explicitly stated. The vulnerabilities collectively represent a high severity risk to affected systems. No known exploits in the wild have been reported.

Mitigation Recommendations

No official patches or fixes are currently available for these vulnerabilities. Red Hat recommends pre-validating any payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters to mitigate the token parsing memory exhaustion issue (CVE-2025-22868). Users should monitor Red Hat advisories for updates and apply patches once released. Since this is not a cloud service, remediation requires user action to update or mitigate.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:23202
Cve Count
7
Additional Cves
["CVE-2025-9714","CVE-2025-22868","CVE-2025-22869","CVE-2025-52565","CVE-2025-59375","CVE-2025-66506"]

Threat ID: 6a160974e29bf47b5063df0c

Added to database: 05/26/2026, 20:58:28 UTC

Last enriched: 08/14/2026, 22:19:22 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 133

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses