Red Hat AI Base Images 3.5.2 Address Component Vulnerabilities

P1 — VALIDATE AND UPDATELow to High · 2.5 / 4.7 / 5.3 / 5.9 / 6.5 / 7.1 / 7.3 / 7.5 / 7.6 / 7.7 / 7.8 / 8.8 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:75652 and RHSA-2026:75654 and RHSA-2026:75655 and RHSA-2026:75657 and RHSA-2026:75658 and RHSA-2026:75659 and RHSA-2026:75660 for Red Hat AI Base Images 3.5 CPU, Neuron, Rubin, CUDA 13, TPU, ROCm 7.14, and Spyre variants. Match entitled systems to the advisory scope, install Red Hat AI Base Images 3.5.2 at the immutable image digests listed in each advisory, validate dependent operations, and retain change evidence.

Validate Red Hat AI Base Images Scope And Apply The Red Hat Fix

What to do now: Inventory Red Hat AI Base Images 3.5 CPU, Neuron, Rubin, CUDA 13, TPU, ROCm 7.14, and Spyre variants, confirm the exact entitled branch and installed build, apply the advisory-listed content, validate representative services, and document exceptions.

Open the authoritative advisory

Last verified: 2026-10-05 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeRed Hat AI Base Images 3.5 CPU, Neuron, Rubin, CUDA 13, TPU, ROCm 7.14, and Spyre variants
AdvisoryRHSA-2026:75652 / RHSA-2026:75654 / RHSA-2026:75655 / RHSA-2026:75657 / RHSA-2026:75658 / RHSA-2026:75659 / RHSA-2026:75660
CVEsCVE-2025-6170, CVE-2026-11940, CVE-2026-15308, CVE-2026-15588, CVE-2026-16118, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858, CVE-2026-54369, CVE-2026-55693, CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211, CVE-2026-57455, CVE-2026-57456, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58049, CVE-2026-59856, CVE-2026-59858, CVE-2026-60002, CVE-2026-64830, CVE-2026-64834, CVE-2026-66036, CVE-2026-66039, CVE-2026-73066, CVE-2026-73072, CVE-2026-73076, CVE-2026-73077, CVE-2026-73078
Authoritative release date2026-10-05 05:43:09 UTC
Authority revision date2026-10-05 14:07:58 UTC
Affected versionsThe supported Red Hat AI Base Images 3.5 CPU, Neuron, Rubin, CUDA 13, TPU, ROCm 7.14, and Spyre variants builds identified as affected in the advisory product-status relationships.
Fixed versionRed Hat AI Base Images 3.5.2 at the immutable image digests listed in each advisory
CVSS base score2.5 / 4.7 / 5.3 / 5.9 / 6.5 / 7.1 / 7.3 / 7.5 / 7.6 / 7.7 / 7.8 / 8.8 (CVSS v3.1)
CVSS severityLow to High
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Red Hat published supported Red Hat AI Base Images replacement content for the advisory-listed CVEs and product branches.

What To Validate Now

  1. Inventory. Locate Red Hat AI Base Images 3.5 CPU, Neuron, Rubin, CUDA 13, TPU, ROCm 7.14, and Spyre variants; record the installed build, repository and entitlement, owner, exposure, dependencies, and maintenance group.
  2. Establish applicability. Compare every system with the product and package relationships in RHSA-2026:75652 and RHSA-2026:75654 and RHSA-2026:75655 and RHSA-2026:75657 and RHSA-2026:75658 and RHSA-2026:75659 and RHSA-2026:75660. Do not infer applicability from the component name or CVSS rating alone.
  3. Remediate. Install Red Hat AI Base Images 3.5.2 at the immutable image digests listed in each advisory from the supported Red Hat channel for the exact branch.
  4. Validate. Confirm the installed package or image digest, exercise representative Red Hat AI Base Images functions and recovery paths, monitor for regressions, and record the result.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Rebuild dependent images from the authority-listed immutable digest; validate accelerator drivers, frameworks, model loading, and provenance before promotion. Preserve pre-change versions, logs, installation output, validation evidence, and any rollback decision.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.