Database/AI/ML frameworks & serving
Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contexts
CVSS 5.5CVE-2022-49784AI/ML frameworks & servingcurated
Impact
Per-CPU northbridge and last-level-cache uncore contexts are allocated but not freed when a CPU comes online, leaking memory on every hotplug. Uncore counters are what you use to measure memory bandwidth and cache behaviour on AMD - i.e. the telemetry an AI operator actually cares about - so this leaks in proportion to how much you monitor.
Who can reach it
Local, driven by CPU hotplug with uncore perf events in use.
What to do
Distro kernel update plus reboot.
References
Related entries
- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelCVE-2024-31584 · PyTorch (flatbuffer loader)Medium
- vLLM: crafted request to the Gemma4 unified parser crashes the inference serverCVE-2026-103241 · vLLM (Gemma4UnifiedParser, rust/src/parser/src/unified/gemma4.rs)Medium
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readCVE-2026-12480 · Keras (HDF5 ExternalLink, incomplete fix)Medium
- Keras: unvalidated dataset sizes in .keras loading let a poisoned model exhaust node memoryCVE-2026-12570 · Keras (.keras model loading, H5IOStore.__getitem__)Medium
- Feast operator: tenant-supplied feature repo code runs with elevated privileges, reaching cluster adminCVE-2026-18942 · Feast operator in Red Hat OpenShift AI (feature repository processing)Medium
- BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the buildCVE-2026-40610 · BentoML (bentoml build, symlink dereferencing in the build context)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.