Skip to main content

Threats Tagged 'cve-2026-53923'

View all threats tagged with 'cve-2026-53923'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-53923

Threats Tagged 'cve-2026-53923'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat® Enterprise Linux® AI is a foundation model platform to seamlessly develop, test, and run Granite family large language models (LLMs) for enterprise applications. This update provides the latest Red Hat Enterprise Linux AI 3.3.6 container images. For a full list of changes in this release, see the Red Hat Enterprise Linux AI Release Notes linked in the References section.

Join the discussion

CVE-2026-44222 is a denial of service vulnerability in vLLM, an inference engine for large language models, as integrated into Red Hat AI Inference Server 3.3.6 (Spyre). Unauthenticated attackers can cause worker termination by submitting malformed multimodal inputs or text prompts with special tokens, disrupting AI inference workloads. No fix is currently available that meets Red Hat's criteria for deployment and stability.

Join the discussion

A vulnerability in vLLM, the inference and serving engine used by Red Hat AI Inference Server, allows an unauthenticated attacker to achieve arbitrary code execution by loading a malicious HuggingFace model while vLLM runs in Python optimized mode. This affects Red Hat AI Inference Server versions prior to 0.22.0 that include the vulnerable pooler activation loader. Exploitation requires the attacker to supply an untrusted model and the server to be running with Python optimization enabled. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for RHEL AI bootc images bundling vLLM. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls.

Join the discussion

A vulnerability in Red Hat AI Inference Server 3.3.6 (CUDA) involves an assert-based security check flaw in the vLLM inference engine for large language models. An unauthenticated attacker can exploit this by publishing a malicious HuggingFace model, potentially achieving arbitrary code execution when vLLM runs in Python optimized mode. The issue affects Red Hat AI Inference Server 3.3 images with vLLM versions prior to 0.14.0. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for bundled vLLM in Enterprise Linux AI bootc images. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization flags, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls.

Join the discussion

vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM's GGUF dequantize kernels (csrc/quantization/gguf/gguf_kernel.cu) causes partial tensor processing. The output tensor is allocated at full size via torch::empty (uninitialized memory), but the dequantize CUDA kernel processes only a truncated number of elements. The unfilled portion of the output tensor retains whatever was previously in GPU memory. In multi-tenant inference deployments, this residual GPU memory may contain tensor data from other users' inference requests, constituting information disclosure. This vulnerability is fixed in 0.23.1rc0.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2026-53923
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses