Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69872

Опубликовано: 11 фев. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

A deserialization flaw was found in python-diskcache. This component uses Python pickle for serialization by default. An attacker with write access to the cache directory can exploit this vulnerability to achieve arbitrary code execution when a victim application reads from the cache. The impact of this flaw is scoped to the user running the tool.

Отчет

Red Hat products are not affected by this flaw in their default state. Multiple default parameters would need to be altered in order for this flaw to exploitable. Products that make use of vLLM would need to be configured to use the outlines backend, a specific environmental variable in the vLLM process namespace would need to be set and the attacker would need to have access to the restricted cache directory. Red Hat customers who do not alter these values are not at risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis-preview/vllm-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-aws-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-azure-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gcp-cuda-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2439059python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization

EPSS

Процентиль: 41%
0.00521
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
6 месяцев назад

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

CVSS3: 9.8
nvd
6 месяцев назад

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

CVSS3: 9.8
debian
6 месяцев назад

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for seri ...

github
6 месяцев назад

DiskCache has unsafe pickle deserialization

EPSS

Процентиль: 41%
0.00521
Низкий

7.6 High

CVSS3