Database/AI/ML frameworks & serving

KServe ModelMesh: Group-writable `/etc/passwd` in the container image
CVSS 6.4CVE-2025-57852AI/ML frameworks & servingcurated
Impact
Group-writable /etc/passwd in the container image → privilege escalation inside the container
Who can reach it
Tenant with code execution in a ModelMesh pod
What to do
Rebuild the container images; no host patch. Provider owns the images if it ships a managed KServe
References
Related entries
- Jupyter Server: login `next` parameter allows redirect to an arbitrary external hostCVE-2025-61669 · Jupyter Server (LoginFormHandler redirect validation)Medium
- vLLM: video decoder limit bypass via sampler subclass shadowing exhausts unaccounted GPU memoryCVE-2026-100649 · vLLM (PyNvVideoCodec decoder allocation, sampler subclass accounting)Medium
- TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIsCVE-2026-15044 · TrustyAI Service Operator (Red Hat OpenShift AI)Medium
- llama.cpp: oversized seq_id in a saved slot file leaks heap memory past the cells arrayCVE-2026-43630 · llama.cpp server (recurrent memory state slot-restore path)Medium
- vLLM: race in the prompt_embeds sparse-tensor guard reopens the CVE-2025-62164 crash pathCVE-2026-73557 · vLLM prompt_embeds loader (safe_load_prompt_embeds sparse-tensor guard)Medium
- Eclipse Che dashboard backend (POST /dashboard/api/data/resolver): The dashboard backend passes a user-supplied URLCVE-2026-86590 · Eclipse Che dashboard backend (POST /dashboard/api/data/resolver)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.