Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 57%

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.4.1 enhancement update

0
High
Published: 06/30/2026 (06/30/2026, 13:53:11 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat® Enterprise Linux® AI is a foundation model platform to seamlessly develop, test, and run Granite family large language models (LLMs) for enterprise applications. This update provides the latest Red Hat Enterprise Linux AI 3.4.1 container disk images for use with OpenShift Virtualization. For a full list of changes in this release, see the Red Hat Enterprise Linux AI Release Notes linked in the References section.

Affected software

Affected versions
>=3.4.0 <3.4.1Red HatRed Hat Enterprise Linux AIRed Hat Enterprise Linux AI 3.4amd64registry.redhat.io/rhelai3/disk-image-cuda-rhel9@sha256:311356cdf57fcbb666da9aa7f502d5799c4cf833597f85390a09c448eade3eae_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:33:10 UTC

Technical Analysis

The advisory covers Red Hat Enterprise Linux AI 3.4.1 container disk image updates for OpenShift Virtualization. Among the vulnerabilities addressed is CVE-2026-39821, a flaw in golang.org/x/net/idna's ToASCII and ToUnicode functions, which incorrectly accept Punycode labels that decode to ASCII-only hostnames, potentially allowing privilege escalation by circumventing hostname validation checks. This affects a broad range of Red Hat products shipping Go toolchain components. The advisory does not explicitly state that a patch is available for this vulnerability but provides updated container images. Additional CVEs (CVE-2026-46595 and CVE-2026-5497) are referenced without detailed descriptions or fixes. The vendor advisory emphasizes upgrading to fixed golang.org/x/net releases when available and rebuilding dependent packages.

Potential Impact

The primary impact is privilege escalation due to improper validation of Punycode-encoded hostnames, which may allow an attacker to bypass hostname restrictions and gain unauthorized access. This affects products shipping the Go toolchain or bundling golang.org/x/net, including Red Hat Enterprise Linux AI and related container builds. No known exploits in the wild have been reported. The severity is rated high by Red Hat based on the potential for elevated privileges and compromised confidentiality and integrity.

Mitigation Recommendations

The vendor advisory recommends upgrading to a fixed version of golang.org/x/net that includes the corrected idna handling and rebuilding dependent packages accordingly. Users should pull the updated Red Hat Enterprise Linux AI 3.4.1 container disk images from the Red Hat container registry for use with OpenShift Virtualization. No explicit patch for CVE-2026-5497 is mentioned. Monitor Red Hat advisories for updates and apply fixes when they become available. No vendor statement indicates that no action is required or that the issue is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:33524
Cve Count
3
Additional Cves
["CVE-2026-39821","CVE-2026-46595"]
Cvss Version
null

Threat ID: 6a4452df27e9c797198e0dcf

Added to database: 06/30/2026, 23:35:59 UTC

Last enriched: 08/10/2026, 18:33:10 UTC

Last updated: 08/14/2026, 08:56:48 UTC

Views: 299

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses