Red Hat AI Inference 3.4.4 requires an image-for-image security refresh
Four advisories map the 3.4.4 CPU, CUDA, ROCm and Spyre images to their CVE sets; the practical response is to replace the deployed variant.
Red Hat issued four Important-severity advisories for Red Hat AI Inference 3.4.4 on August 20. The advisories are split by accelerator image, so operators should map the image they actually run to the matching advisory rather than treat 3.4.4 as one undifferentiated update.
The advisory-to-image map
The CPU image is covered by RHSA-2026:57380, CUDA by RHSA-2026:57389, ROCm by RHSA-2026:57390 and Spyre by RHSA-2026:57387. CPU, CUDA and ROCm list the same five vulnerabilities: CVE-2026-34753, CVE-2026-34755, CVE-2026-34756, CVE-2026-41523 and CVE-2026-44223.
Spyre includes those five and adds CVE-2026-40192 plus CVE-2026-42308, CVE-2026-42309, CVE-2026-42310 and CVE-2026-42311. That makes the Spyre advisory a ten-CVE update, while each other variant lists five.
What the errata do — and do not — say
Each advisory identifies Red Hat AI Inference Server as the affected product and states that its corresponding 3.4.4 image is available. The public pages do not list separate package fixes, mitigations or workarounds; their Fixes sections say “none.” They therefore support a narrow operational conclusion: this is an image replacement, not a configuration-only mitigation.
The advisory pages also do not provide enough detail to infer exploitability for a particular serving deployment. Operators needing that assessment should follow the individual CVE records and their own exposure model rather than deriving severity from the number of entries alone.
Replacement action
Inventory the image variant and immutable digest used by every Red Hat AI Inference workload. Pull the corresponding 3.4.4 image from the entitled registry, update the deployment reference, and roll the serving pods. Then verify that every replacement pod resolves to the new digest; changing a mutable tag without confirming the running digest is not a reliable completion check.
CPU, CUDA and ROCm deployments share the same published CVE set, but they still have distinct advisories and images. Spyre deployments need the Spyre-specific replacement because its advisory carries the additional five CVEs. Where an organization mirrors images into a disconnected registry, the mirror and deployment reference both need to move before the rollout is complete.
sources
- RHSA-2026:57380 — Red Hat AI Inference 3.4.4 (CPU)access.redhat.com
- RHSA-2026:57389 — Red Hat AI Inference 3.4.4 (CUDA)access.redhat.com
- RHSA-2026:57390 — Red Hat AI Inference 3.4.4 (ROCm)access.redhat.com
- RHSA-2026:57387 — Red Hat AI Inference 3.4.4 (Spyre)access.redhat.com
comments · 0