Medium [CVE-2026-12480] Information disclosure via malicious model archive with Virtual Dataset
This medium-severity Red Hat Linux advisory covers CVE-2026-12480 affecting Red Hat OpenShift AI (RHOAI).
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets.
This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem.
When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.
A flaw was found in Keras. This vulnerability leads to information disclosure, allowing an attacker to access sensitive data from the victim's filesystem.
Moderate: This information disclosure flaw in Keras affects Red Hat OpenShift AI components that utilize Keras. Exploitation requires user interaction, specifically loading an untrusted model, which limits the attack vector to scenarios where users process external, potentially malicious, model files.
Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-22.
Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.
- 3.13.2
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
- 3.12.2
- 3.14.1
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Mitigation
Upgrade to a fixed release: 3.12.2, 3.14.1. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.