Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49121

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.

A flaw was found in AI Tensor Engine for ROCm (AITER). This vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending a specially crafted data package, known as a pickle payload, to a ZeroMQ (ZMQ) subscriber socket. This exploitation is possible due to a lack of authentication, message integrity checks (HMAC), or format validation in the MessageQueue.recv() function. Successful exploitation can lead to arbitrary code execution on every remote reader worker, posing a critical risk to the system's integrity and confidentiality.

Отчет

Red Hat AI Inference Server and Red Hat OpenShift AI ship the AI Tensor Engine for ROCm (AITER) Python package as a dependency in ROCm-based vLLM container images. Affected streams embed AITER versions 0.1.5 through 0.1.10.post2 (published to PyPI under the distribution name amd-aiter, which is the same upstream ROCm/aiter project — its own setup.py sets PACKAGE_NAME = "amd-aiter"), all of which are within the upstream affected range (0.1.14 and earlier). The flaw is an unauthenticated remote code execution vulnerability in AITER MessageQueue.recv() (shm_broadcast.py), where data received on a ZeroMQ subscriber socket is deserialized with Python pickle without authentication or integrity checks (CWE-502). Red Hat rates this issue as Important. Our CVSS score reflects high attack complexity: exploitation requires network access to the inference worker ZMQ XPUB endpoint on the cluster network, or the ability to supply a forged distributed Handle with an attacker-controlled subscribe address. This is not a default remote attack against an unauthenticated internet-facing service. Engineering trackers are filed for affected product streams. Updated container images will be released when a fixed AITER version is available and integrated.

Меры по смягчению последствий

Mitigate this issue by limiting network access to AITER/vLLM inference worker ZMQ endpoints to trusted cluster nodes only. Do not expose XPUB/subscribe ports outside the cluster network. Where multi-node ROCm inference is not required, prefer single-node deployments that bind ZMQ to localhost where supported. Update to a fixed AITER release (upstream fix expected in 0.1.15 or later) when provided in updated Red Hat AI Inference Server and Red Hat OpenShift AI container images. Refer to the errata or advisory linked from this CVE page when available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-azure-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-rocm-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2483882aiter: AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization

EPSS

Процентиль: 63%
0.01104
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
2 месяца назад

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.

CVSS3: 8.1
github
2 месяца назад

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.

EPSS

Процентиль: 63%
0.01104
Низкий

8.1 High

CVSS3