{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49121.json"
      }
    ],
    "title": "aiter: AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization",
    "tracking": {
      "current_release_date": "2026-07-04T07:54:08+00:00",
      "generator": {
        "date": "2026-07-04T07:54:08+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.1"
        }
      },
      "id": "CVE-2026-49121",
      "initial_release_date": "2026-06-01T17:09:18.607000+00:00",
      "revision_history": [
        {
          "date": "2026-06-01T17:09:18.607000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-04T07:47:42+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-04T07:54:08+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat AI Inference Server",
                "product": {
                  "name": "Red Hat AI Inference Server",
                  "product_id": "red_hat_ai_inference_server",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ai_inference_server:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat AI Inference Server"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
                "product": {
                  "name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
                  "product_id": "red_hat_enterprise_linux_ai_(rhel_ai)_3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux AI (RHEL AI) 3"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "rhaiis/vllm-rocm-rhel9",
            "product": {
              "name": "rhaiis/vllm-rocm-rhel9",
              "product_id": "rhaiis/vllm-rocm-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/vllm-rocm-rhel9?repository_url=registry.redhat.io/rhaiis/vllm-rocm-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhaii/vllm-rocm-rhel9",
            "product": {
              "name": "rhaii/vllm-rocm-rhel9",
              "product_id": "rhaii/vllm-rocm-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/vllm-rocm-rhel9?repository_url=registry.redhat.io/rhaii/vllm-rocm-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhelai3/bootc-azure-rocm-rhel9",
            "product": {
              "name": "rhelai3/bootc-azure-rocm-rhel9",
              "product_id": "rhelai3/bootc-azure-rocm-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/bootc-azure-rocm-rhel9?repository_url=registry.redhat.io/rhelai3/bootc-azure-rocm-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhelai3/bootc-rocm-rhel9",
            "product": {
              "name": "rhelai3/bootc-rocm-rhel9",
              "product_id": "rhelai3/bootc-rocm-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/bootc-rocm-rhel9?repository_url=registry.redhat.io/rhelai3/bootc-rocm-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-vllm-rocm-rhel9",
            "product": {
              "name": "rhoai/odh-vllm-rocm-rhel9",
              "product_id": "rhoai/odh-vllm-rocm-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-vllm-rocm-rhel9?repository_url=registry.redhat.io/rhoai/odh-vllm-rocm-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhaii/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server",
          "product_id": "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9"
        },
        "product_reference": "rhaii/vllm-rocm-rhel9",
        "relates_to_product_reference": "red_hat_ai_inference_server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhaiis/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server",
          "product_id": "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9"
        },
        "product_reference": "rhaiis/vllm-rocm-rhel9",
        "relates_to_product_reference": "red_hat_ai_inference_server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhelai3/bootc-azure-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3",
          "product_id": "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9"
        },
        "product_reference": "rhelai3/bootc-azure-rocm-rhel9",
        "relates_to_product_reference": "red_hat_enterprise_linux_ai_(rhel_ai)_3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhelai3/bootc-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3",
          "product_id": "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9"
        },
        "product_reference": "rhelai3/bootc-rocm-rhel9",
        "relates_to_product_reference": "red_hat_enterprise_linux_ai_(rhel_ai)_3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-vllm-rocm-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
        },
        "product_reference": "rhoai/odh-vllm-rocm-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-49121",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "discovery_date": "2026-06-01T19:01:30.600496+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2483882"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in AI Tensor Engine for ROCm (AITER). This vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending a specially crafted data package, known as a pickle payload, to a ZeroMQ (ZMQ) subscriber socket. This exploitation is possible due to a lack of authentication, message integrity checks (HMAC), or format validation in the MessageQueue.recv() function. Successful exploitation can lead to arbitrary code execution on every remote reader worker, posing a critical risk to the system's integrity and confidentiality.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "aiter: AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Red Hat AI Inference Server and Red Hat OpenShift AI ship the AI Tensor Engine for ROCm (AITER) Python package as a dependency in ROCm-based vLLM container images. Affected streams embed AITER versions 0.1.5 through 0.1.10.post2 (published to PyPI under the distribution name amd-aiter, which is the same upstream ROCm/aiter project — its own setup.py sets PACKAGE_NAME = \"amd-aiter\"), all of which are within the upstream affected range (0.1.14 and earlier).\n\nThe flaw is an unauthenticated remote code execution vulnerability in AITER MessageQueue.recv() (shm_broadcast.py), where data received on a ZeroMQ subscriber socket is deserialized with Python pickle without authentication or integrity checks (CWE-502).\n\nRed Hat rates this issue as Important. Our CVSS score reflects high attack complexity: exploitation requires network access to the inference worker ZMQ XPUB endpoint on the cluster network, or the ability to supply a forged distributed Handle with an attacker-controlled subscribe address. This is not a default remote attack against an unauthenticated internet-facing service.\n\nEngineering trackers are filed for affected product streams. Updated container images will be released when a fixed AITER version is available and integrated.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9",
          "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9",
          "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9",
          "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-49121"
        },
        {
          "category": "external",
          "summary": "RHBZ#2483882",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2483882"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-49121",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49121"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-49121",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49121"
        },
        {
          "category": "external",
          "summary": "https://github.com/ROCm/aiter/issues/3076",
          "url": "https://github.com/ROCm/aiter/issues/3076"
        },
        {
          "category": "external",
          "summary": "https://github.com/ROCm/aiter/pull/3170",
          "url": "https://github.com/ROCm/aiter/pull/3170"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/ai-tensor-engine-for-rocm-aiter-unauthenticated-rce-via-messagequeue-recv-pickle-deserialization",
          "url": "https://www.vulncheck.com/advisories/ai-tensor-engine-for-rocm-aiter-unauthenticated-rce-via-messagequeue-recv-pickle-deserialization"
        }
      ],
      "release_date": "2026-06-01T17:09:18.607000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Mitigate this issue by limiting network access to AITER/vLLM inference worker ZMQ endpoints to trusted cluster nodes only. Do not expose XPUB/subscribe ports outside the cluster network.\n\nWhere multi-node ROCm inference is not required, prefer single-node deployments that bind ZMQ to localhost where supported.\n\nUpdate to a fixed AITER release (upstream fix expected in 0.1.15 or later) when provided in updated Red Hat AI Inference Server and Red Hat OpenShift AI container images. Refer to the errata or advisory linked from this CVE page when available.",
          "product_ids": [
            "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9",
            "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9",
            "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9",
            "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_ai_inference_server:rhaii/vllm-rocm-rhel9",
            "red_hat_ai_inference_server:rhaiis/vllm-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-azure-rocm-rhel9",
            "red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-rocm-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-vllm-rocm-rhel9"
          ]
        }
      ],
      "title": "aiter: AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization"
    }
  ]
}