Skip to main content
EPSS 0.2%top 88%

Red Hat Security Advisory: RHOAI 2.22.3 - Red Hat OpenShift AI

0
High
Published: 12/04/2025 (12/04/2025, 13:06:08 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 2.22.3 provides these changes:

Affected software

Affected versions
>=2.22.0 <2.22.3Red HatRed Hat OpenShift AIRed Hat OpenShift AI 2.22amd64registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:8b3e0152680063828a54187feec06600de866db91ab219911b1c3ab50d8b1b7c_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:21:30 UTC

Technical Analysis

The vulnerability CVE-2025-9905 in Red Hat OpenShift AI (RHOAI) versions >=2.22.0 <2.22.3 is a path traversal flaw originating from the keras Python library's use of tarfile.extractall without proper filtering. An attacker can craft malicious tar archives containing special symlinks that, when extracted with the extract=True option, allow writing arbitrary files outside the intended directory. This can lead to unauthorized code execution, file modification, or data disclosure. The issue is tracked under multiple CWEs including CWE-22 (Path Traversal) and CWE-913 (Improper Control of Dynamically-Managed Code Resources). Red Hat has released RHOAI 2.22.3 with updated images to mitigate this vulnerability. The vendor advisory notes no known exploits in the wild and provides upgrade instructions.

Potential Impact

Successful exploitation allows a remote attacker to write arbitrary files anywhere on the filesystem outside the intended extraction folder, potentially leading to unauthorized code execution, modification or creation of critical files, disclosure of sensitive information, or denial of service by corrupting essential files. The vulnerability affects confidentiality, integrity, and availability of the affected systems. No active exploitation has been reported.

Mitigation Recommendations

Red Hat has released RHOAI version 2.22.3 which addresses this vulnerability. Users should upgrade their Red Hat OpenShift AI clusters to version 2.22.3 following the official Red Hat documentation and upgrade instructions. No alternative mitigations meeting Red Hat's criteria are currently available. Applying the official update is the recommended and supported remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:22759
Cve Count
8
Additional Cves
["CVE-2025-12060","CVE-2025-47907","CVE-2025-53643","CVE-2025-58183","CVE-2025-58754","CVE-2025-62156","CVE-2025-62727"]

Threat ID: 6a175ed3e29bf47b50ed8ca2

Added to database: 05/27/2026, 21:14:59 UTC

Last enriched: 08/14/2026, 22:21:30 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 98

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses