Database/AI/ML frameworks & serving

llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplication
CVSS 7.8CVE-2026-43627AI/ML frameworks & servingcurated
Impact
Integer overflow from unchecked multiplication
Who can reach it
Tenant-controlled batch parameters
What to do
Rebuild past b9058
References
Related entries
- HuggingFace transformers: Critical RCE in all versions before 5.3.0CVE-2026-4372 · HuggingFace transformersHigh
- stable-diffusion.cpp: Memory-safety flaw in model loadingCVE-2026-47749 · stable-diffusion.cppHigh
- PyTorch Lightning (`_load_state`): RCE by importing and executing classes named in the checkpointCVE-2026-58659 · PyTorch Lightning (`_load_state`)High
- NVIDIA Megatron Bridge: deserialization of untrusted checkpoints or configs gives code executionCVE-2026-61750 · NVIDIA Megatron BridgeHigh
- NVIDIA NemoClaw: OS command injection in the status and logs plugin commandsCVE-2026-65089 · NVIDIA NemoClaw for Linux (status and logs plugin commands)High
- NVIDIA NemoClaw: OS command injection in the NIM management componentCVE-2026-65090 · NVIDIA NemoClaw for Linux (NIM management component)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.