List of fixed Common Vulnerabilities and Exposures in Cloudera Data Services on premises 1.5.5 SP3 CHF3

Review the Common vulnerabilities and Exposures (CVEs) that were fixed in Cloudera Data Services on premises 1.5.5 SP3 CHF3 release.

CVE IDDescriptionLibrary Path
CVE-1999-0236 ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

huelb

CVE-1999-1237 Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

huelb

CVE-1999-1412 A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

huelb

CVE-2007-0086 The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal

huelb

CVE-2007-0450 Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

huelb

CVE-2007-3641 archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.

ml-runtime-pbj-conda-standard

CVE-2007-3644 archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

ml-runtime-pbj-conda-standard

CVE-2007-3645 archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.

ml-runtime-pbj-conda-standard

CVE-2011-1777 Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.

ml-runtime-pbj-conda-standard

CVE-2011-1778 Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.

ml-runtime-pbj-conda-standard

CVE-2011-4461 Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

databus-producer
dex_thunderhead-dbuswxmclient
obs_agent

CVE-2015-5237 protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

admissiond
catalogd
cdc-profilers
cdc_profilers
cml-addon-hadoop-cli-7.1.9.20000-24
cml-addon-hadoop-cli-7.3.1.200-90
cml-addon-hadoop-cli-7.3.1.709-1
dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-livy-runtime-2.4.8-7.1.9.1078
dex-livy-runtime-3.3.2-7.1.9.1078
dex-livy-runtime-3.3.2-7.1.9.1078-compat
dex-livy-runtime-3.5.4-7.1.9.1078
dex-livy-runtime-3.5.4-7.3.1.709
dex-livy-server-2.4.8-7.1.9.1078
dex-livy-server-3.3.2-7.1.9.1078
dex-livy-server-3.5.4-7.1.9.1078
dex-livy-server-3.5.4-7.3.1.709
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-spark-history-server-2.4.8-7.1.9.1078
dex-spark-history-server-3.3.2-7.1.9.1078
dex-spark-history-server-3.5.4-7.1.9.1078
dex-spark-history-server-3.5.4-7.3.1.709
dex-spark-runtime-2.4.8-7.1.9.1078
dex-spark-runtime-3.3.2-7.1.9.1078
dex-spark-runtime-3.3.2-7.1.9.1078-compat
dex-spark-runtime-3.5.4-7.1.9.1078
dex-spark-runtime-3.5.4-7.3.1.709
hive
impalad_coord_exec
impalad_coordinator
impalad_executor
ozone-parcel-image

CVE-2016-1252 The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures.

cdsw-s2i-builder-buildah

CVE-2016-2510 BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.

trino

CVE-2016-6524 These are all security issues fixed in the jupyter-notebook-6.2.0-1.4 package on the GA media of openSUSE Tumbleweed.

hue

CVE-2016-10735 In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2017-11164 In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.

cml-addon-hadoop-cli-7.3.1.200-90
ml-runtime-pbj-workbench-r4.5-standard
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v2.0.3

CVE-2017-14992 Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.

cdsw-s2i-builder-buildah

CVE-2018-3721 lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

cdsw-web

CVE-2018-8115 A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.

cdsw-s2i-builder-buildah

CVE-2018-12608 An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.

cdsw-s2i-builder-buildah

CVE-2018-14040 In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2018-14041 In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2018-14042 In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2018-16487 A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

cdsw-web

CVE-2018-20676 In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2018-20677 In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2019-8331 In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0

CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

hive

CVE-2019-16884 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

cdsw-s2i-builder-buildah

CVE-2019-19794 The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

cdsw-s2i-builder-buildah

CVE-2019-19921 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

cdsw-s2i-builder-buildah

CVE-2019-1010266 lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.

cdsw-web

CVE-2020-15257 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain socket. This would allow malicious containers running in the same network namespace as the shim, with an effective UID of 0 but otherwise reduced privileges, to cause new processes to be run with elevated privileges. This vulnerability has been fixed in containerd 1.3.9 and 1.4.3. Users should update to these versions as soon as they are released. It should be noted that containers started with an old version of containerd-shim should be stopped and restarted, as running containers will continue to be vulnerable even after an upgrade. If you are not providing the ability for untrusted users to start containers in the same network namespace as the shim (typically the "host" network namespace, for example with docker run --net=host or hostNetwork: true in a Kubernetes pod) and run with an effective UID of 0, you are not vulnerable to this issue. If you are running containers with a vulnerable configuration, you can deny access to all abstract sockets with AppArmor by adding a line similar to deny unix addr=@**, to your policy. It is best practice to run containers with a reduced set of privileges, with a non-zero UID, and with isolated namespaces. The containerd maintainers strongly advise against sharing namespaces with the host. Reducing the set of isolation mechanisms used for a container necessarily increases that container's privilege, regardless of what container runtime is used for running that container.

cdsw-s2i-builder-buildah

CVE-2021-21334 In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected containers have different security contexts, this may allow sensitive information to be unintentionally shared. If you are not using containerd's CRI implementation (through one of the mechanisms described above), you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image which have different environment variables, you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image in rapid succession, you have reduced likelihood of being vulnerable to this issue This vulnerability has been fixed in containerd 1.3.10 and containerd 1.4.4. Users should update to these versions.

cdsw-s2i-builder-buildah

CVE-2021-30465 runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.

cdsw-s2i-builder-buildah

CVE-2021-47639 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be _no_ references to the page after the mmu_notifier returns. The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm_set_pfn_dirty() when zapping SPTEs, and thus completing a zap of an invalid root _after_ the mmu_notifier returns is fatal. WARNING: CPU: 24 PID: 1496 at arch/x86/kvm/../../../virt/kvm/kvm_main.c:173 [kvm] RIP: 0010:kvm_is_zone_device_pfn+0x96/0xa0 [kvm] Call Trace: <TASK> kvm_set_pfn_dirty+0xa8/0xe0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] zap_gfn_range+0x1f3/0x310 [kvm] kvm_tdp_mmu_zap_invalidated_roots+0x50/0x90 [kvm] kvm_mmu_zap_all_fast+0x177/0x1a0 [kvm] set_nx_huge_pages+0xb4/0x190 [kvm] param_attr_store+0x70/0x100 module_attr_store+0x19/0x30 kernfs_fop_write_iter+0x119/0x1b0 new_sync_write+0x11c/0x1b0 vfs_write+0x1cc/0x270 ksys_write+0x5f/0xe0 do_syscall_64+0x38/0xc0 entry_SYSCALL_64_after_hwframe+0x44/0xae </TASK>

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2021-47657 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() If virtio_gpu_object_shmem_init() fails (e.g. due to fault injection, as it happened in the bug report by syzbot), virtio_gpu_array_put_free() could be called with objs equal to NULL. Ensure that objs is not NULL in virtio_gpu_array_put_free(), or otherwise return from the function.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-24999 qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).

cloudera-ai-rag-studio

CVE-2022-39253 Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same volume), Git copies the contents of the source's `$GIT_DIR/objects` directory into the destination by either creating hardlinks to the source contents, or copying them (if hardlinks are disabled via `--no-hardlinks`). A malicious actor could convince a victim to clone a repository with a symbolic link pointing at sensitive information on the victim's machine. This can be done either by having the victim clone a malicious repository on the same machine, or having them clone a malicious repository embedded as a bare repository via a submodule from any source, provided they clone with the `--recurse-submodules` option. Git does not create symbolic links in the `$GIT_DIR/objects` directory. The problem has been patched in the versions published on 2022-10-18, and backported to v2.30.x. Potential workarounds: Avoid cloning untrusted repositories using the `--local` optimization when on a shared machine, either by passing the `--no-local` option to `git clone` or cloning from a URL that uses the `file://` scheme. Alternatively, avoid cloning repositories from untrusted sources with `--recurse-submodules` or run `git config --global protocol.file.allow user`.

cdsw-s2i-builder-buildah

CVE-2022-48988 In the Linux kernel, the following vulnerability has been resolved: memcg: fix possible use-after-free in memcg_write_event_control() memcg_write_event_control() accesses the dentry->d_name of the specified control fd to route the write call. As a cgroup interface file can't be renamed, it's safe to access d_name as long as the specified file is a regular cgroup file. Also, as these cgroup interface files can't be removed before the directory, it's safe to access the parent too. Prior to 347c4a874710 ("memcg: remove cgroup_event->cft"), there was a call to __file_cft() which verified that the specified file is a regular cgroupfs file before further accesses. The cftype pointer returned from __file_cft() was no longer necessary and the commit inadvertently dropped the file type check with it allowing any file to slip through. With the invarients broken, the d_name and parent accesses can now race against renames and removals of arbitrary files and cause use-after-free's. Fix the bug by resurrecting the file type check in __file_cft(). Now that cgroupfs is implemented through kernfs, checking the file operations needs to go through a layer of indirection. Instead, let's check the superblock and dentry type.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49060 In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereference in smc_pnet_find_ib() dev_name() was called with dev.parent as argument but without to NULL-check it before. Solve this by checking the pointer before the call to dev_name().

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49127 In the Linux kernel, the following vulnerability has been resolved: ref_tracker: implement use-after-free detection Whenever ref_tracker_dir_init() is called, mark the struct ref_tracker_dir as dead. Test the dead status from ref_tracker_alloc() and ref_tracker_free() This should detect buggy dev_put()/dev_hold() happening too late in netdevice dismantle process.

nim-meta-llama3.3-70b-instruct-v2.0.3
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v2.0.3

CVE-2022-49129 In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been scheduled. Ensure the work item is canceled so we do not have use-after-free crash in case cleanup is called before the work item is executed. This fixes crash on my x86_64 apu2 when mt7921k radio fails to work. Radio still fails, but OS does not crash.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49130 In the Linux kernel, the following vulnerability has been resolved: ath11k: mhi: use mhi_sync_power_up() If amss.bin was missing ath11k would crash during 'rmmod ath11k_pci'. The reason for that was that we were using mhi_async_power_up() which does not check any errors. But mhi_sync_power_up() on the other hand does check for errors so let's use that to fix the crash. I was not able to find a reason why an async version was used. ath11k_mhi_start() (which enables state ATH11K_MHI_POWER_ON) is called from ath11k_hif_power_up(), which can sleep. So sync version should be safe to use here. [ 145.569731] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC KASAN PTI [ 145.569789] KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] [ 145.569843] CPU: 2 PID: 1628 Comm: rmmod Kdump: loaded Tainted: G W 5.16.0-wt-ath+ #567 [ 145.569898] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021 [ 145.569956] RIP: 0010:ath11k_hal_srng_access_begin+0xb5/0x2b0 [ath11k] [ 145.570028] Code: df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 ec 01 00 00 48 8b ab a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 ea 48 c1 ea 03 <0f> b6 14 02 48 89 e8 83 e0 07 83 c0 03 45 85 ed 75 48 38 d0 7c 08 [ 145.570089] RSP: 0018:ffffc900025d7ac0 EFLAGS: 00010246 [ 145.570144] RAX: dffffc0000000000 RBX: ffff88814fca2dd8 RCX: 1ffffffff50cb455 [ 145.570196] RDX: 0000000000000000 RSI: ffff88814fca2dd8 RDI: ffff88814fca2e80 [ 145.570252] RBP: 0000000000000000 R08: 0000000000000000 R09: ffffffffa8659497 [ 145.570329] R10: fffffbfff50cb292 R11: 0000000000000001 R12: ffff88814fca0000 [ 145.570410] R13: 0000000000000000 R14: ffff88814fca2798 R15: ffff88814fca2dd8 [ 145.570465] FS: 00007fa399988540(0000) GS:ffff888233e00000(0000) knlGS:0000000000000000 [ 145.570519] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 145.570571] CR2: 00007fa399b51421 CR3: 0000000137898002 CR4: 00000000003706e0 [ 145.570623] Call Trace: [ 145.570675] <TASK> [ 145.570727] ? ath11k_ce_tx_process_cb+0x34b/0x860 [ath11k] [ 145.570797] ath11k_ce_tx_process_cb+0x356/0x860 [ath11k] [ 145.570864] ? tasklet_init+0x150/0x150 [ 145.570919] ? ath11k_ce_alloc_pipes+0x280/0x280 [ath11k] [ 145.570986] ? tasklet_clear_sched+0x42/0xe0 [ 145.571042] ? tasklet_kill+0xe9/0x1b0 [ 145.571095] ? tasklet_clear_sched+0xe0/0xe0 [ 145.571148] ? irq_has_action+0x120/0x120 [ 145.571202] ath11k_ce_cleanup_pipes+0x45a/0x580 [ath11k] [ 145.571270] ? ath11k_pci_stop+0x10e/0x170 [ath11k_pci] [ 145.571345] ath11k_core_stop+0x8a/0xc0 [ath11k] [ 145.571434] ath11k_core_deinit+0x9e/0x150 [ath11k] [ 145.571499] ath11k_pci_remove+0xd2/0x260 [ath11k_pci] [ 145.571553] pci_device_remove+0x9a/0x1c0 [ 145.571605] __device_release_driver+0x332/0x660 [ 145.571659] driver_detach+0x1e7/0x2c0 [ 145.571712] bus_remove_driver+0xe2/0x2d0 [ 145.571772] pci_unregister_driver+0x21/0x250 [ 145.571826] __do_sys_delete_module+0x30a/0x4b0 [ 145.571879] ? free_module+0xac0/0xac0 [ 145.571933] ? lockdep_hardirqs_on_prepare.part.0+0x18c/0x370 [ 145.571986] ? syscall_enter_from_user_mode+0x1d/0x50 [ 145.572039] ? lockdep_hardirqs_on+0x79/0x100 [ 145.572097] do_syscall_64+0x3b/0x90 [ 145.572153] entry_SYSCALL_64_after_hwframe+0x44/0xae Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03003-QCAHSPSWPL_V1_V2_SILICONZ_LITE-2

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49136 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is set hci_cmd_sync_queue shall return an error if HCI_UNREGISTER flag has been set as that means hci_unregister_dev has been called so it will likely cause a uaf after the timeout as the hdev will be freed.

nim-meta-llama3.3-70b-instruct-v2.0.3
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v2.0.3

CVE-2022-49235 In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix uninit value bugs Syzbot reported 2 KMSAN bugs in ath9k. All of them are caused by missing field initialization. In htc_connect_service() svc_meta_len and pad are not initialized. Based on code it looks like in current skb there is no service data, so simply initialize svc_meta_len to 0. htc_issue_send() does not initialize htc_frame_hdr::control array. Based on firmware code, it will initialize it by itself, so simply zero whole array to make KMSAN happy Fail logs: BUG: KMSAN: kernel-usb-infoleak in usb_submit_urb+0x6c1/0x2aa0 drivers/usb/core/urb.c:430 usb_submit_urb+0x6c1/0x2aa0 drivers/usb/core/urb.c:430 hif_usb_send_regout drivers/net/wireless/ath/ath9k/hif_usb.c:127 [inline] hif_usb_send+0x5f0/0x16f0 drivers/net/wireless/ath/ath9k/hif_usb.c:479 htc_issue_send drivers/net/wireless/ath/ath9k/htc_hst.c:34 [inline] htc_connect_service+0x143e/0x1960 drivers/net/wireless/ath/ath9k/htc_hst.c:275 ... Uninit was created at: slab_post_alloc_hook mm/slab.h:524 [inline] slab_alloc_node mm/slub.c:3251 [inline] __kmalloc_node_track_caller+0xe0c/0x1510 mm/slub.c:4974 kmalloc_reserve net/core/skbuff.c:354 [inline] __alloc_skb+0x545/0xf90 net/core/skbuff.c:426 alloc_skb include/linux/skbuff.h:1126 [inline] htc_connect_service+0x1029/0x1960 drivers/net/wireless/ath/ath9k/htc_hst.c:258 ... Bytes 4-7 of 18 are uninitialized Memory access of size 18 starts at ffff888027377e00 BUG: KMSAN: kernel-usb-infoleak in usb_submit_urb+0x6c1/0x2aa0 drivers/usb/core/urb.c:430 usb_submit_urb+0x6c1/0x2aa0 drivers/usb/core/urb.c:430 hif_usb_send_regout drivers/net/wireless/ath/ath9k/hif_usb.c:127 [inline] hif_usb_send+0x5f0/0x16f0 drivers/net/wireless/ath/ath9k/hif_usb.c:479 htc_issue_send drivers/net/wireless/ath/ath9k/htc_hst.c:34 [inline] htc_connect_service+0x143e/0x1960 drivers/net/wireless/ath/ath9k/htc_hst.c:275 ... Uninit was created at: slab_post_alloc_hook mm/slab.h:524 [inline] slab_alloc_node mm/slub.c:3251 [inline] __kmalloc_node_track_caller+0xe0c/0x1510 mm/slub.c:4974 kmalloc_reserve net/core/skbuff.c:354 [inline] __alloc_skb+0x545/0xf90 net/core/skbuff.c:426 alloc_skb include/linux/skbuff.h:1126 [inline] htc_connect_service+0x1029/0x1960 drivers/net/wireless/ath/ath9k/htc_hst.c:258 ... Bytes 16-17 of 18 are uninitialized Memory access of size 18 starts at ffff888027377e00

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49288 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49294 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check if modulo is 0 before dividing. [How & Why] If a value of 0 is read, then this will cause a divide-by-0 panic.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49316 In the Linux kernel, the following vulnerability has been resolved: NFSv4: Don't hold the layoutget locks across multiple RPC calls When doing layoutget as part of the open() compound, we have to be careful to release the layout locks before we can call any further RPC calls, such as setattr(). The reason is that those calls could trigger a recall, which could deadlock.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49323 In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: fix possible null-ptr-deref in arm_smmu_device_probe() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49349 In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in ext4_rename_dir_prepare We got issue as follows: EXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue ext4_get_first_dir_block: bh->b_data=0xffff88810bee6000 len=34478 ext4_get_first_dir_block: *parent_de=0xffff88810beee6ae bh->b_data=0xffff88810bee6000 ext4_rename_dir_prepare: [1] parent_de=0xffff88810beee6ae ================================================================== BUG: KASAN: use-after-free in ext4_rename_dir_prepare+0x152/0x220 Read of size 4 at addr ffff88810beee6ae by task rep/1895 CPU: 13 PID: 1895 Comm: rep Not tainted 5.10.0+ #241 Call Trace: dump_stack+0xbe/0xf9 print_address_description.constprop.0+0x1e/0x220 kasan_report.cold+0x37/0x7f ext4_rename_dir_prepare+0x152/0x220 ext4_rename+0xf44/0x1ad0 ext4_rename2+0x11c/0x170 vfs_rename+0xa84/0x1440 do_renameat2+0x683/0x8f0 __x64_sys_renameat+0x53/0x60 do_syscall_64+0x33/0x40 entry_SYSCALL_64_after_hwframe+0x44/0xa9 RIP: 0033:0x7f45a6fc41c9 RSP: 002b:00007ffc5a470218 EFLAGS: 00000246 ORIG_RAX: 0000000000000108 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f45a6fc41c9 RDX: 0000000000000005 RSI: 0000000020000180 RDI: 0000000000000005 RBP: 00007ffc5a470240 R08: 00007ffc5a470160 R09: 0000000020000080 R10: 00000000200001c0 R11: 0000000000000246 R12: 0000000000400bb0 R13: 00007ffc5a470320 R14: 0000000000000000 R15: 0000000000000000 The buggy address belongs to the page: page:00000000440015ce refcount:0 mapcount:0 mapping:0000000000000000 index:0x1 pfn:0x10beee flags: 0x200000000000000() raw: 0200000000000000 ffffea00043ff4c8 ffffea0004325608 0000000000000000 raw: 0000000000000001 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff88810beee580: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88810beee600: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff >ffff88810beee680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ^ ffff88810beee700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88810beee780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ================================================================== Disabling lock debugging due to kernel taint ext4_rename_dir_prepare: [2] parent_de->inode=3537895424 ext4_rename_dir_prepare: [3] dir=0xffff888124170140 ext4_rename_dir_prepare: [4] ino=2 ext4_rename_dir_prepare: ent->dir->i_ino=2 parent=-757071872 Reason is first directory entry which 'rec_len' is 34478, then will get illegal parent entry. Now, we do not check directory entry after read directory block in 'ext4_get_first_dir_block'. To solve this issue, check directory entry in 'ext4_get_first_dir_block'. [ Trigger an ext4_error() instead of just warning if the directory is missing a '.' or '..' entry. Also make sure we return an error code if the file system is corrupted. -TYT ]

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49371 In the Linux kernel, the following vulnerability has been resolved: driver core: fix deadlock in __device_attach In __device_attach function, The lock holding logic is as follows: ... __device_attach device_lock(dev) // get lock dev async_schedule_dev(__device_attach_async_helper, dev); // func async_schedule_node async_schedule_node_domain(func) entry = kzalloc(sizeof(struct async_entry), GFP_ATOMIC); /* when fail or work limit, sync to execute func, but __device_attach_async_helper will get lock dev as well, which will lead to A-A deadlock. */ if (!entry || atomic_read(&entry_count) > MAX_WORK) { func; else queue_work_node(node, system_unbound_wq, &entry->work) device_unlock(dev) As shown above, when it is allowed to do async probes, because of out of memory or work limit, async work is not allowed, to do sync execute instead. it will lead to A-A deadlock because of __device_attach_async_helper getting lock dev. To fix the deadlock, move the async_schedule_dev outside device_lock, as we can see, in async_schedule_node_domain, the parameter of queue_work_node is system_unbound_wq, so it can accept concurrent operations. which will also not change the code logic, and will not lead to deadlock.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49374 In the Linux kernel, the following vulnerability has been resolved: tipc: check attribute length for bearer name syzbot reported uninit-value: ===================================================== BUG: KMSAN: uninit-value in string_nocheck lib/vsprintf.c:644 [inline] BUG: KMSAN: uninit-value in string+0x4f9/0x6f0 lib/vsprintf.c:725 string_nocheck lib/vsprintf.c:644 [inline] string+0x4f9/0x6f0 lib/vsprintf.c:725 vsnprintf+0x2222/0x3650 lib/vsprintf.c:2806 vprintk_store+0x537/0x2150 kernel/printk/printk.c:2158 vprintk_emit+0x28b/0xab0 kernel/printk/printk.c:2256 vprintk_default+0x86/0xa0 kernel/printk/printk.c:2283 vprintk+0x15f/0x180 kernel/printk/printk_safe.c:50 _printk+0x18d/0x1cf kernel/printk/printk.c:2293 tipc_enable_bearer net/tipc/bearer.c:371 [inline] __tipc_nl_bearer_enable+0x2022/0x22a0 net/tipc/bearer.c:1033 tipc_nl_bearer_enable+0x6c/0xb0 net/tipc/bearer.c:1042 genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline] - Do sanity check the attribute length for TIPC_NLA_BEARER_NAME. - Do not use 'illegal name' in printing message.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49404 In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Fix potential integer multiplication overflow errors When multiplying of different types, an overflow is possible even when storing the result in a larger type. This is because the conversion is done after the multiplication. So arithmetic overflow and thus in incorrect value is possible. Correct an instance of this in the inter packet delay calculation. Fix by ensuring one of the operands is u64 which will promote the other to u64 as well ensuring no overflow.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49416 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLACE_NONE, we free the old context in ieee80211_vif_use_reserved_reassign(). Therefore, we cannot check the old_ctx anymore, so we should set it to NULL after this point. However, since the new_ctx replace state is clearly not IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do anything else in this function and can just return to avoid accessing the freed old_ctx.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49492 In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix a NULL pointer dereference in nvme_alloc_admin_tags In nvme_alloc_admin_tags, the admin_q can be set to an error (typically -ENOMEM) if the blk_mq_init_queue call fails to set up the queue, which is checked immediately after the call. However, when we return the error message up the stack, to nvme_reset_work the error takes us to nvme_remove_dead_ctrl() nvme_dev_disable() nvme_suspend_queue(&dev->queues[0]). Here, we only check that the admin_q is non-NULL, rather than not an error or NULL, and begin quiescing a queue that never existed, leading to bad / NULL pointer dereference.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49536 In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix SCSI I/O completion and abort handler deadlock During stress I/O tests with 500+ vports, hard LOCKUP call traces are observed. CPU A: native_queued_spin_lock_slowpath+0x192 _raw_spin_lock_irqsave+0x32 lpfc_handle_fcp_err+0x4c6 lpfc_fcp_io_cmd_wqe_cmpl+0x964 lpfc_sli4_fp_handle_cqe+0x266 __lpfc_sli4_process_cq+0x105 __lpfc_sli4_hba_process_cq+0x3c lpfc_cq_poll_hdler+0x16 irq_poll_softirq+0x76 __softirqentry_text_start+0xe4 irq_exit+0xf7 do_IRQ+0x7f CPU B: native_queued_spin_lock_slowpath+0x5b _raw_spin_lock+0x1c lpfc_abort_handler+0x13e scmd_eh_abort_handler+0x85 process_one_work+0x1a7 worker_thread+0x30 kthread+0x112 ret_from_fork+0x1f Diagram of lockup: CPUA CPUB ---- ---- lpfc_cmd->buf_lock phba->hbalock lpfc_cmd->buf_lock phba->hbalock Fix by reordering the taking of the lpfc_cmd->buf_lock and phba->hbalock in lpfc_abort_handler routine so that it tries to take the lpfc_cmd->buf_lock first before phba->hbalock.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49538 In the Linux kernel, the following vulnerability has been resolved: ALSA: jack: Access input_dev under mutex It is possible when using ASoC that input_dev is unregistered while calling snd_jack_report, which causes NULL pointer dereference. In order to prevent this serialize access to input_dev using mutex lock.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49577 In the Linux kernel, the following vulnerability has been resolved: udp: Fix a data-race around sysctl_udp_l3mdev_accept. While reading sysctl_udp_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49583 In the Linux kernel, the following vulnerability has been resolved: iavf: Fix handling of dummy receive descriptors Fix memory leak caused by not handling dummy receive descriptor properly. iavf_get_rx_buffer now sets the rx_buffer return value for dummy receive descriptors. Without this patch, when the hardware writes a dummy descriptor, iavf would not free the page allocated for the previous receive buffer. This is an unlikely event but can still happen. [Jesse: massaged commit message]

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49615 In the Linux kernel, the following vulnerability has been resolved: ASoC: rt711-sdca: fix kernel NULL pointer dereference when IO error The initial settings will be written before the codec probe function. But, the rt711->component doesn't be assigned yet. If IO error happened during initial settings operations, it will cause the kernel panic. This patch changed component->dev to slave->dev to fix this issue.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49626 In the Linux kernel, the following vulnerability has been resolved: sfc: fix use after free when disabling sriov Use after free is detected by kfence when disabling sriov. What was read after being freed was vf->pci_dev: it was freed from pci_disable_sriov and later read in efx_ef10_sriov_free_vf_vports, called from efx_ef10_sriov_free_vf_vswitching. Set the pointer to NULL at release time to not trying to read it later. Reproducer and dmesg log (note that kfence doesn't detect it every time): $ echo 1 > /sys/class/net/enp65s0f0np0/device/sriov_numvfs $ echo 0 > /sys/class/net/enp65s0f0np0/device/sriov_numvfs BUG: KFENCE: use-after-free read in efx_ef10_sriov_free_vf_vswitching+0x82/0x170 [sfc] Use-after-free read at 0x00000000ff3c1ba5 (in kfence-#224): efx_ef10_sriov_free_vf_vswitching+0x82/0x170 [sfc] efx_ef10_pci_sriov_disable+0x38/0x70 [sfc] efx_pci_sriov_configure+0x24/0x40 [sfc] sriov_numvfs_store+0xfe/0x140 kernfs_fop_write_iter+0x11c/0x1b0 new_sync_write+0x11f/0x1b0 vfs_write+0x1eb/0x280 ksys_write+0x5f/0xe0 do_syscall_64+0x5c/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae kfence-#224: 0x00000000edb8ef95-0x00000000671f5ce1, size=2792, cache=kmalloc-4k allocated by task 6771 on cpu 10 at 3137.860196s: pci_alloc_dev+0x21/0x60 pci_iov_add_virtfn+0x2a2/0x320 sriov_enable+0x212/0x3e0 efx_ef10_sriov_configure+0x67/0x80 [sfc] efx_pci_sriov_configure+0x24/0x40 [sfc] sriov_numvfs_store+0xba/0x140 kernfs_fop_write_iter+0x11c/0x1b0 new_sync_write+0x11f/0x1b0 vfs_write+0x1eb/0x280 ksys_write+0x5f/0xe0 do_syscall_64+0x5c/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae freed by task 6771 on cpu 12 at 3170.991309s: device_release+0x34/0x90 kobject_cleanup+0x3a/0x130 pci_iov_remove_virtfn+0xd9/0x120 sriov_disable+0x30/0xe0 efx_ef10_pci_sriov_disable+0x57/0x70 [sfc] efx_pci_sriov_configure+0x24/0x40 [sfc] sriov_numvfs_store+0xfe/0x140 kernfs_fop_write_iter+0x11c/0x1b0 new_sync_write+0x11f/0x1b0 vfs_write+0x1eb/0x280 ksys_write+0x5f/0xe0 do_syscall_64+0x5c/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49636 In the Linux kernel, the following vulnerability has been resolved: vlan: fix memory leak in vlan_newlink() Blamed commit added back a bug I fixed in commit 9bbd917e0bec ("vlan: fix memory leak in vlan_dev_set_egress_priority") If a memory allocation fails in vlan_changelink() after other allocations succeeded, we need to call vlan_dev_free_egress_priority() to free all allocated memory because after a failed ->newlink() we do not call any methods like ndo_uninit() or dev->priv_destructor(). In following example, if the allocation for last element 2000:2001 fails, we need to free eight prior allocations: ip link add link dummy0 dummy0.100 type vlan id 100 \ egress-qos-map 1:2 2:3 3:4 4:5 5:6 6:7 7:8 8:9 2000:2001 syzbot report was: BUG: memory leak unreferenced object 0xffff888117bd1060 (size 32): comm "syz-executor408", pid 3759, jiffies 4294956555 (age 34.090s) hex dump (first 32 bytes): 09 00 00 00 00 a0 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<ffffffff83fc60ad>] kmalloc include/linux/slab.h:600 [inline] [<ffffffff83fc60ad>] vlan_dev_set_egress_priority+0xed/0x170 net/8021q/vlan_dev.c:193 [<ffffffff83fc6628>] vlan_changelink+0x178/0x1d0 net/8021q/vlan_netlink.c:128 [<ffffffff83fc67c8>] vlan_newlink+0x148/0x260 net/8021q/vlan_netlink.c:185 [<ffffffff838b1278>] rtnl_newlink_create net/core/rtnetlink.c:3363 [inline] [<ffffffff838b1278>] __rtnl_newlink+0xa58/0xdc0 net/core/rtnetlink.c:3580 [<ffffffff838b1629>] rtnl_newlink+0x49/0x70 net/core/rtnetlink.c:3593 [<ffffffff838ac66c>] rtnetlink_rcv_msg+0x21c/0x5c0 net/core/rtnetlink.c:6089 [<ffffffff839f9c37>] netlink_rcv_skb+0x87/0x1d0 net/netlink/af_netlink.c:2501 [<ffffffff839f8da7>] netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline] [<ffffffff839f8da7>] netlink_unicast+0x397/0x4c0 net/netlink/af_netlink.c:1345 [<ffffffff839f9266>] netlink_sendmsg+0x396/0x710 net/netlink/af_netlink.c:1921 [<ffffffff8384dbf6>] sock_sendmsg_nosec net/socket.c:714 [inline] [<ffffffff8384dbf6>] sock_sendmsg+0x56/0x80 net/socket.c:734 [<ffffffff8384e15c>] ____sys_sendmsg+0x36c/0x390 net/socket.c:2488 [<ffffffff838523cb>] ___sys_sendmsg+0x8b/0xd0 net/socket.c:2542 [<ffffffff838525b8>] __sys_sendmsg net/socket.c:2571 [inline] [<ffffffff838525b8>] __do_sys_sendmsg net/socket.c:2580 [inline] [<ffffffff838525b8>] __se_sys_sendmsg net/socket.c:2578 [inline] [<ffffffff838525b8>] __x64_sys_sendmsg+0x78/0xf0 net/socket.c:2578 [<ffffffff845ad8d5>] do_syscall_x64 arch/x86/entry/common.c:50 [inline] [<ffffffff845ad8d5>] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 [<ffffffff8460006a>] entry_SYSCALL_64_after_hwframe+0x46/0xb0

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49639 In the Linux kernel, the following vulnerability has been resolved: cipso: Fix data-races around sysctl. While reading cipso sysctl variables, they can be changed concurrently. So, we need to add READ_ONCE() to avoid data-races.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49644 In the Linux kernel, the following vulnerability has been resolved: drm/i915: fix a possible refcount leak in intel_dp_add_mst_connector() If drm_connector_init fails, intel_connector_free will be called to take care of proper free. So it is necessary to drop the refcount of port before intel_connector_free. (cherry picked from commit cea9ed611e85d36a05db52b6457bf584b7d969e2)

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49647 In the Linux kernel, the following vulnerability has been resolved: cgroup: Use separate src/dst nodes when preloading css_sets for migration Each cset (css_set) is pinned by its tasks. When we're moving tasks around across csets for a migration, we need to hold the source and destination csets to ensure that they don't go away while we're moving tasks about. This is done by linking cset->mg_preload_node on either the mgctx->preloaded_src_csets or mgctx->preloaded_dst_csets list. Using the same cset->mg_preload_node for both the src and dst lists was deemed okay as a cset can't be both the source and destination at the same time. Unfortunately, this overloading becomes problematic when multiple tasks are involved in a migration and some of them are identity noop migrations while others are actually moving across cgroups. For example, this can happen with the following sequence on cgroup1: #1> mkdir -p /sys/fs/cgroup/misc/a/b #2> echo $$ > /sys/fs/cgroup/misc/a/cgroup.procs #3> RUN_A_COMMAND_WHICH_CREATES_MULTIPLE_THREADS & #4> PID=$! #5> echo $PID > /sys/fs/cgroup/misc/a/b/tasks #6> echo $PID > /sys/fs/cgroup/misc/a/cgroup.procs the process including the group leader back into a. In this final migration, non-leader threads would be doing identity migration while the group leader is doing an actual one. After #3, let's say the whole process was in cset A, and that after #4, the leader moves to cset B. Then, during #6, the following happens: 1. cgroup_migrate_add_src() is called on B for the leader. 2. cgroup_migrate_add_src() is called on A for the other threads. 3. cgroup_migrate_prepare_dst() is called. It scans the src list. 4. It notices that B wants to migrate to A, so it tries to A to the dst list but realizes that its ->mg_preload_node is already busy. 5. and then it notices A wants to migrate to A as it's an identity migration, it culls it by list_del_init()'ing its ->mg_preload_node and putting references accordingly. 6. The rest of migration takes place with B on the src list but nothing on the dst list. This means that A isn't held while migration is in progress. If all tasks leave A before the migration finishes and the incoming task pins it, the cset will be destroyed leading to use-after-free. This is caused by overloading cset->mg_preload_node for both src and dst preload lists. We wanted to exclude the cset from the src list but ended up inadvertently excluding it from the dst list too. This patch fixes the issue by separating out cset->mg_preload_node into ->mg_src_preload_node and ->mg_dst_preload_node, so that the src and dst preloadings don't interfere with each other.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49653 In the Linux kernel, the following vulnerability has been resolved: i2c: piix4: Fix a memory leak in the EFCH MMIO support The recently added support for EFCH MMIO regions introduced a memory leak in that code path. The leak is caused by the fact that release_resource() merely removes the resource from the tree but does not free its memory. We need to call release_mem_region() instead, which does free the memory. As a nice side effect, this brings back some symmetry between the legacy and MMIO paths.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49664 In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer dereference crash: [] BUG: kernel NULL pointer dereference, address: 0000000000000068 [] RIP: 0010:tipc_link_is_up+0x5/0x10 [tipc] [] Call Trace: [] <IRQ> [] tipc_bcast_rcv+0xa2/0x190 [tipc] [] tipc_node_bc_rcv+0x8b/0x200 [tipc] [] tipc_rcv+0x3af/0x5b0 [tipc] [] tipc_udp_recv+0xc7/0x1e0 [tipc] It was caused by the 'l' passed into tipc_bcast_rcv() is NULL. When it creates a node in tipc_node_check_dest(), after inserting the new node into hashtable in tipc_node_create(), it creates the bc link. However, there is a gap between this insert and bc link creation, a bc packet may come in and get the node from the hashtable then try to dereference its bc link, which is NULL. This patch is to fix it by moving the bc link creation before inserting into the hashtable. Note that for a preliminary node becoming "real", the bc link creation should also be called before it's rehashed, as we don't create it for preliminary nodes.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49671 In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix memory leak in ib_cm_insert_listen cm_alloc_id_priv() allocates resource for the cm_id_priv. When cm_init_listen() fails it doesn't free it, leading to memory leak. Add the missing error unwind.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49700 In the Linux kernel, the following vulnerability has been resolved: mm/slub: add missing TID updates on slab deactivation The fastpath in slab_alloc_node() assumes that c->slab is stable as long as the TID stays the same. However, two places in __slab_alloc() currently don't update the TID when deactivating the CPU slab. If multiple operations race the right way, this could lead to an object getting lost; or, in an even more unlikely situation, it could even lead to an object being freed onto the wrong slab's freelist, messing up the `inuse` counter and eventually causing a page to be freed to the page allocator while it still contains slab objects. (I haven't actually tested these cases though, this is just based on looking at the code. Writing testcases for this stuff seems like it'd be a pain...) The race leading to state inconsistency is (all operations on the same CPU and kmem_cache): - task A: begin do_slab_free(): - read TID - read pcpu freelist (==NULL) - check `slab == c->slab` (true) - [PREEMPT A->B] - task B: begin slab_alloc_node(): - fastpath fails (`c->freelist` is NULL) - enter __slab_alloc() - slub_get_cpu_ptr() (disables preemption) - enter ___slab_alloc() - take local_lock_irqsave() - read c->freelist as NULL - get_freelist() returns NULL - write `c->slab = NULL` - drop local_unlock_irqrestore() - goto new_slab - slub_percpu_partial() is NULL - get_partial() returns NULL - slub_put_cpu_ptr() (enables preemption) - [PREEMPT B->A] - task A: finish do_slab_free(): - this_cpu_cmpxchg_double() succeeds() - [CORRUPT STATE: c->slab==NULL, c->freelist!=NULL] From there, the object on c->freelist will get lost if task B is allowed to continue from here: It will proceed to the retry_load_slab label, set c->slab, then jump to load_freelist, which clobbers c->freelist. But if we instead continue as follows, we get worse corruption: - task A: run __slab_free() on object from other struct slab: - CPU_PARTIAL_FREE case (slab was on no list, is now on pcpu partial) - task A: run slab_alloc_node() with NUMA node constraint: - fastpath fails (c->slab is NULL) - call __slab_alloc() - slub_get_cpu_ptr() (disables preemption) - enter ___slab_alloc() - c->slab is NULL: goto new_slab - slub_percpu_partial() is non-NULL - set c->slab to slub_percpu_partial(c) - [CORRUPT STATE: c->slab points to slab-1, c->freelist has objects from slab-2] - goto redo - node_match() fails - goto deactivate_slab - existing c->freelist is passed into deactivate_slab() - inuse count of slab-1 is decremented to account for object from slab-2 At this point, the inuse count of slab-1 is 1 lower than it should be. This means that if we free all allocated objects in slab-1 except for one, SLUB will think that slab-1 is completely unused, and may free its page, leading to use-after-free.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49853 In the Linux kernel, the following vulnerability has been resolved: net: macvlan: fix memory leaks of macvlan_common_newlink kmemleak reports memory leaks in macvlan_common_newlink, as follows: ip link add link eth0 name .. type macvlan mode source macaddr add <MAC-ADDR> kmemleak reports: unreferenced object 0xffff8880109bb140 (size 64): comm "ip", pid 284, jiffies 4294986150 (age 430.108s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 b8 aa 5a 12 80 88 ff ff ..........Z..... 80 1b fa 0d 80 88 ff ff 1e ff ac af c7 c1 6b 6b ..............kk backtrace: [<ffffffff813e06a7>] kmem_cache_alloc_trace+0x1c7/0x300 [<ffffffff81b66025>] macvlan_hash_add_source+0x45/0xc0 [<ffffffff81b66a67>] macvlan_changelink_sources+0xd7/0x170 [<ffffffff81b6775c>] macvlan_common_newlink+0x38c/0x5a0 [<ffffffff81b6797e>] macvlan_newlink+0xe/0x20 [<ffffffff81d97f8f>] __rtnl_newlink+0x7af/0xa50 [<ffffffff81d98278>] rtnl_newlink+0x48/0x70 ... In the scenario where the macvlan mode is configured as 'source', macvlan_changelink_sources() will be execured to reconfigure list of remote source mac addresses, at the same time, if register_netdevice() return an error, the resource generated by macvlan_changelink_sources() is not cleaned up. Using this patch, in the case of an error, it will execute macvlan_flush_sources() to ensure that the resource is cleaned up.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49885 In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() Change num_ghes from int to unsigned int, preventing an overflow and causing subsequent vmalloc() to fail. The overflow happens in ghes_estatus_pool_init() when calculating len during execution of the statement below as both multiplication operands here are signed int: len += (num_ghes * GHES_ESOURCE_PREALLOC_MAX_SIZE); The following call trace is observed because of this bug: [ 9.317108] swapper/0: vmalloc error: size 18446744071562596352, exceeds total pages, mode:0xcc0(GFP_KERNEL), nodemask=(null),cpuset=/,mems_allowed=0-1 [ 9.317131] Call Trace: [ 9.317134] <TASK> [ 9.317137] dump_stack_lvl+0x49/0x5f [ 9.317145] dump_stack+0x10/0x12 [ 9.317146] warn_alloc.cold+0x7b/0xdf [ 9.317150] ? __device_attach+0x16a/0x1b0 [ 9.317155] __vmalloc_node_range+0x702/0x740 [ 9.317160] ? device_add+0x17f/0x920 [ 9.317164] ? dev_set_name+0x53/0x70 [ 9.317166] ? platform_device_add+0xf9/0x240 [ 9.317168] __vmalloc_node+0x49/0x50 [ 9.317170] ? ghes_estatus_pool_init+0x43/0xa0 [ 9.317176] vmalloc+0x21/0x30 [ 9.317177] ghes_estatus_pool_init+0x43/0xa0 [ 9.317179] acpi_hest_init+0x129/0x19c [ 9.317185] acpi_init+0x434/0x4a4 [ 9.317188] ? acpi_sleep_proc_init+0x2a/0x2a [ 9.317190] do_one_initcall+0x48/0x200 [ 9.317195] kernel_init_freeable+0x221/0x284 [ 9.317200] ? rest_init+0xe0/0xe0 [ 9.317204] kernel_init+0x1a/0x130 [ 9.317205] ret_from_fork+0x22/0x30 [ 9.317208] </TASK> [ rjw: Subject and changelog edits ]

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49908 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix memory leak in vhci_write Syzkaller reports a memory leak as follows: ==================================== BUG: memory leak unreferenced object 0xffff88810d81ac00 (size 240): [...] hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<ffffffff838733d9>] __alloc_skb+0x1f9/0x270 net/core/skbuff.c:418 [<ffffffff833f742f>] alloc_skb include/linux/skbuff.h:1257 [inline] [<ffffffff833f742f>] bt_skb_alloc include/net/bluetooth/bluetooth.h:469 [inline] [<ffffffff833f742f>] vhci_get_user drivers/bluetooth/hci_vhci.c:391 [inline] [<ffffffff833f742f>] vhci_write+0x5f/0x230 drivers/bluetooth/hci_vhci.c:511 [<ffffffff815e398d>] call_write_iter include/linux/fs.h:2192 [inline] [<ffffffff815e398d>] new_sync_write fs/read_write.c:491 [inline] [<ffffffff815e398d>] vfs_write+0x42d/0x540 fs/read_write.c:578 [<ffffffff815e3cdd>] ksys_write+0x9d/0x160 fs/read_write.c:631 [<ffffffff845e0645>] do_syscall_x64 arch/x86/entry/common.c:50 [inline] [<ffffffff845e0645>] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 [<ffffffff84600087>] entry_SYSCALL_64_after_hwframe+0x63/0xcd ==================================== HCI core will uses hci_rx_work() to process frame, which is queued to the hdev->rx_q tail in hci_recv_frame() by HCI driver. Yet the problem is that, HCI core may not free the skb after handling ACL data packets. To be more specific, when start fragment does not contain the L2CAP length, HCI core just copies skb into conn->rx_skb and finishes frame process in l2cap_recv_acldata(), without freeing the skb, which triggers the above memory leak. This patch solves it by releasing the relative skb, after processing the above case in l2cap_recv_acldata().

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-49949 In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Fix memory leak in firmware upload In the case of firmware-upload, an instance of struct fw_upload is allocated in firmware_upload_register(). This data needs to be freed in fw_dev_release(). Create a new fw_upload_free() function in sysfs_upload.c to handle the firmware-upload specific memory frees and incorporate the missing kfree call for the fw_upload structure.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50170 In the Linux kernel, the following vulnerability has been resolved: kunit: executor: Fix a memory leak on failure in kunit_filter_tests It's possible that memory allocation for 'filtered' will fail, but for the copy of the suite to succeed. In this case, the copy could be leaked. Properly free 'copy' in the error case for the allocation of 'filtered' failing. Note that there may also have been a similar issue in kunit_filter_subsuites, before it was removed in "kunit: flatten kunit_suite*** to kunit_suite** in .kunit_test_suites". This was reported by clang-analyzer via the kernel test robot, here: https://lore.kernel.org/all/c8073b8e-7b9e-0830-4177-87c12f16349c@intel.com/ And by smatch via Dan Carpenter and the kernel test robot: https://lore.kernel.org/all/202207101328.ASjx88yj-lkp@intel.com/

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50562 In the Linux kernel, the following vulnerability has been resolved: tpm: acpi: Call acpi_put_table() to fix memory leak The start and length of the event log area are obtained from TPM2 or TCPA table, so we call acpi_get_table() to get the ACPI information, but the acpi_get_table() should be coupled with acpi_put_table() to release the ACPI memory, add the acpi_put_table() properly to fix the memory leak. While we are at it, remove the redundant empty line at the end of the tpm_read_log_acpi().

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50615 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix reference count leak in snr_uncore_mmio_map() pci_get_device() will increase the reference count for the returned pci_dev, so snr_uncore_get_mc_dev() will return a pci_dev with its reference count increased. We need to call pci_dev_put() to decrease the reference count. Let's add the missing pci_dev_put().

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50617 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/powerplay/psm: Fix memory leak in power state init Commit 902bc65de0b3 ("drm/amdgpu/powerplay/psm: return an error in power state init") made the power state init function return early in case of failure to get an entry from the powerplay table, but it missed to clean up the allocated memory for the current power state before returning.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50619 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in kfd_mem_dmamap_userptr() If the number of pages from the userptr BO differs from the SG BO then the allocated memory for the SG table doesn't get freed before returning -EINVAL, which may lead to a memory leak in some error paths. Fix this by checking the number of pages before allocating memory for the SG table.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50626 In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: fix memory leak in dvb_usb_adapter_init() Syzbot reports a memory leak in "dvb_usb_adapter_init()". The leak is due to not accounting for and freeing current iteration's adapter->priv in case of an error. Currently if an error occurs, it will exit before incrementing "num_adapters_initalized", which is used as a reference counter to free all adap->priv in "dvb_usb_adapter_exit()". There are multiple error paths that can exit from before incrementing the counter. Including the error handling paths for "dvb_usb_adapter_stream_init()", "dvb_usb_adapter_dvb_init()" and "dvb_usb_adapter_frontend_init()" within "dvb_usb_adapter_init()". This means that in case of an error in any of these functions the current iteration is not accounted for and the current iteration's adap->priv is not freed. Fix this by freeing the current iteration's adap->priv in the "stream_init_err:" label in the error path. The rest of the (accounted for) adap->priv objects are freed in dvb_usb_adapter_exit() as expected using the num_adapters_initalized variable. Syzbot report: BUG: memory leak unreferenced object 0xffff8881172f1a00 (size 512): comm "kworker/0:2", pid 139, jiffies 4294994873 (age 10.960s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<ffffffff844af012>] dvb_usb_adapter_init drivers/media/usb/dvb-usb/dvb-usb-init.c:75 [inline] [<ffffffff844af012>] dvb_usb_init drivers/media/usb/dvb-usb/dvb-usb-init.c:184 [inline] [<ffffffff844af012>] dvb_usb_device_init.cold+0x4e5/0x79e drivers/media/usb/dvb-usb/dvb-usb-init.c:308 [<ffffffff830db21d>] dib0700_probe+0x8d/0x1b0 drivers/media/usb/dvb-usb/dib0700_core.c:883 [<ffffffff82d3fdc7>] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396 [<ffffffff8274ab37>] call_driver_probe drivers/base/dd.c:542 [inline] [<ffffffff8274ab37>] really_probe.part.0+0xe7/0x310 drivers/base/dd.c:621 [<ffffffff8274ae6c>] really_probe drivers/base/dd.c:583 [inline] [<ffffffff8274ae6c>] __driver_probe_device+0x10c/0x1e0 drivers/base/dd.c:752 [<ffffffff8274af6a>] driver_probe_device+0x2a/0x120 drivers/base/dd.c:782 [<ffffffff8274b786>] __device_attach_driver+0xf6/0x140 drivers/base/dd.c:899 [<ffffffff82747c87>] bus_for_each_drv+0xb7/0x100 drivers/base/bus.c:427 [<ffffffff8274b352>] __device_attach+0x122/0x260 drivers/base/dd.c:970 [<ffffffff827498f6>] bus_probe_device+0xc6/0xe0 drivers/base/bus.c:487 [<ffffffff82745cdb>] device_add+0x5fb/0xdf0 drivers/base/core.c:3405 [<ffffffff82d3d202>] usb_set_configuration+0x8f2/0xb80 drivers/usb/core/message.c:2170 [<ffffffff82d4dbfc>] usb_generic_driver_probe+0x8c/0xc0 drivers/usb/core/generic.c:238 [<ffffffff82d3f49c>] usb_probe_device+0x5c/0x140 drivers/usb/core/driver.c:293 [<ffffffff8274ab37>] call_driver_probe drivers/base/dd.c:542 [inline] [<ffffffff8274ab37>] really_probe.part.0+0xe7/0x310 drivers/base/dd.c:621 [<ffffffff8274ae6c>] really_probe drivers/base/dd.c:583 [inline] [<ffffffff8274ae6c>] __driver_probe_device+0x10c/0x1e0 drivers/base/dd.c:752

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50630 In the Linux kernel, the following vulnerability has been resolved: mm: hugetlb: fix UAF in hugetlb_handle_userfault The vma_lock and hugetlb_fault_mutex are dropped before handling userfault and reacquire them again after handle_userfault(), but reacquire the vma_lock could lead to UAF[1,2] due to the following race, hugetlb_fault hugetlb_no_page /*unlock vma_lock */ hugetlb_handle_userfault handle_userfault /* unlock mm->mmap_lock*/ vm_mmap_pgoff do_mmap mmap_region munmap_vma_range /* clean old vma */ /* lock vma_lock again <--- UAF */ /* unlock vma_lock */ Since the vma_lock will unlock immediately after hugetlb_handle_userfault(), let's drop the unneeded lock and unlock in hugetlb_handle_userfault() to fix the issue. [1] https://lore.kernel.org/linux-mm/000000000000d5e00a05e834962e@google.com/ [2] https://lore.kernel.org/linux-mm/20220921014457.1668-1-liuzixian4@huawei.com/

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50667 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix memory leak in vmw_mksstat_add_ioctl() If the copy of the description string from userspace fails, then the page for the instance descriptor doesn't get freed before returning -EFAULT, which leads to a memleak.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2022-50717 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds check on Transfer Tag ttag is used as an index to get cmd in nvmet_tcp_handle_h2c_data_pdu(), add a bounds check to avoid out-of-bounds access.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-6992 Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.

dex_haveged

CVE-2023-23931 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-7.3.2.0
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-airflow-api-server-7.3.2.0
dex-airflow-connections-7.1.9.1078
dex-airflow-connections-7.3.1.709
dex-airflow-connections-7.3.2.0
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-runtime-airflow-python-builder-7.3.2.0
hue

CVE-2023-29483 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-7.3.2.0
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-airflow-api-server-7.3.2.0
dex-airflow-connections-7.1.9.1078
dex-airflow-connections-7.3.1.709
dex-airflow-connections-7.3.2.0
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-runtime-airflow-python-builder-7.3.2.0
hue

CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

cdp-private
parcel

CVE-2023-48713 Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless containers. An attacker who controls a pod to a degree where they can control the responses from the /metrics endpoint can cause Denial-of-Service of the autoscaler from an unbound memory allocation bug. This is a DoS vulnerability, where a non-privileged Knative user can cause a DoS for the cluster. This issue has been patched in version 0.39.0.

api
authorizer

CVE-2023-49081 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability only occurs if the attacker can control the HTTP version of the request. This issue has been patched in version 3.9.0.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2023-49082 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2023-49083 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-7.3.2.0
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-airflow-api-server-7.3.2.0
dex-airflow-connections-7.1.9.1078
dex-airflow-connections-7.3.1.709
dex-airflow-connections-7.3.2.0
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-runtime-airflow-python-builder-7.3.2.0
hue

CVE-2023-49290 lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in JWE's algorithm PBES2-* could lead to a denial of service. The JWE key management algorithms based on PBKDF2 require a JOSE Header Parameter called p2c (PBES2 Count). This parameter dictates the number of PBKDF2 iterations needed to derive a CEK wrapping key. Its primary purpose is to intentionally slow down the key derivation function, making password brute-force and dictionary attacks more resource- intensive. Therefore, if an attacker sets the p2c parameter in JWE to a very large number, it can cause a lot of computational consumption, resulting in a denial of service. This vulnerability has been addressed in commit `64f2a229b` which has been included in release version 1.2.27 and 2.0.18. Users are advised to upgrade. There are no known workarounds for this vulnerability.

install-cni
pilot

CVE-2023-52924 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and preparation phase if the following conditions are met: 1. set is a verdict map ("1.2.3.4 : jump foo") 2. timeouts are enabled In this case, following sequence is problematic: 1. element E in set S refers to chain C 2. userspace requests removal of set S 3. kernel does a set walk to decrement chain->use count for all elements from preparation phase 4. kernel does another set walk to remove elements from the commit phase (or another walk to do a chain->use increment for all elements from abort phase) If E has already expired in 1), it will be ignored during list walk, so its use count won't have been changed. Then, when set is culled, ->destroy callback will zap the element via nf_tables_set_elem_destroy(), but this function is only safe for elements that have been deactivated earlier from the preparation phase: lack of earlier deactivate removes the element but leaks the chain use count, which results in a WARN splat when the chain gets removed later, plus a leak of the nft_chain structure. Update pipapo_get() not to skip expired elements, otherwise flush command reports bogus ENOENT errors.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-52931 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Avoid potential vm use-after-free Adding the vm to the vm_xa table makes it visible to userspace, which could try to race with us to close the vm. So we need to take our extra reference before putting it in the table. (cherry picked from commit 99343c46d4e2b34c285d3d5f68ff04274c2f9fb4)

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-52937 In the Linux kernel, the following vulnerability has been resolved: HV: hv_balloon: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-52938 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Don't attempt to resume the ports before they exist This will fix null pointer dereference that was caused by the driver attempting to resume ports that were not yet registered.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-52973 In the Linux kernel, the following vulnerability has been resolved: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF After a call to console_unlock() in vcs_read() the vc_data struct can be freed by vc_deallocate(). Because of that, the struct vc_data pointer load must be done at the top of while loop in vcs_read() to avoid a UAF when vcs_size() is called. Syzkaller reported a UAF in vcs_size(). BUG: KASAN: use-after-free in vcs_size (drivers/tty/vt/vc_screen.c:215) Read of size 4 at addr ffff8881137479a8 by task 4a005ed81e27e65/1537 CPU: 0 PID: 1537 Comm: 4a005ed81e27e65 Not tainted 6.2.0-rc5 #1 Hardware name: Red Hat KVM, BIOS 1.15.0-2.module Call Trace: <TASK> __asan_report_load4_noabort (mm/kasan/report_generic.c:350) vcs_size (drivers/tty/vt/vc_screen.c:215) vcs_read (drivers/tty/vt/vc_screen.c:415) vfs_read (fs/read_write.c:468 fs/read_write.c:450) ... </TASK> Allocated by task 1191: ... kmalloc_trace (mm/slab_common.c:1069) vc_allocate (./include/linux/slab.h:580 ./include/linux/slab.h:720 drivers/tty/vt/vt.c:1128 drivers/tty/vt/vt.c:1108) con_install (drivers/tty/vt/vt.c:3383) tty_init_dev (drivers/tty/tty_io.c:1301 drivers/tty/tty_io.c:1413 drivers/tty/tty_io.c:1390) tty_open (drivers/tty/tty_io.c:2080 drivers/tty/tty_io.c:2126) chrdev_open (fs/char_dev.c:415) do_dentry_open (fs/open.c:883) vfs_open (fs/open.c:1014) ... Freed by task 1548: ... kfree (mm/slab_common.c:1021) vc_port_destruct (drivers/tty/vt/vt.c:1094) tty_port_destructor (drivers/tty/tty_port.c:296) tty_port_put (drivers/tty/tty_port.c:312) vt_disallocate_all (drivers/tty/vt/vt_ioctl.c:662 (discriminator 2)) vt_ioctl (drivers/tty/vt/vt_ioctl.c:903) tty_ioctl (drivers/tty/tty_io.c:2776) ... The buggy address belongs to the object at ffff888113747800 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 424 bytes inside of 1024-byte region [ffff888113747800, ffff888113747c00) The buggy address belongs to the physical page: page:00000000b3fe6c7c refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x113740 head:00000000b3fe6c7c order:3 compound_mapcount:0 subpages_mapcount:0 compound_pincount:0 anon flags: 0x17ffffc0010200(slab|head|node=0|zone=2|lastcpupid=0x1fffff) raw: 0017ffffc0010200 ffff888100042dc0 0000000000000000 dead000000000001 raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff888113747880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff888113747900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb > ffff888113747980: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff888113747a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff888113747a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ================================================================== Disabling lock debugging due to kernel taint

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53013 In the Linux kernel, the following vulnerability has been resolved: ptdma: pt_core_execute_cmd() should use spinlock The interrupt handler (pt_core_irq_handler()) of the ptdma driver can be called from interrupt context. The code flow in this function can lead down to pt_core_execute_cmd() which will attempt to grab a mutex, which is not appropriate in interrupt context and ultimately leads to a kernel panic. The fix here changes this mutex to a spinlock, which has been verified to resolve the issue.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53015 In the Linux kernel, the following vulnerability has been resolved: HID: betop: check shape of output reports betopff_init() only checks the total sum of the report counts for each report field to be at least 4, but hid_betopff_play() expects 4 report fields. A device advertising an output report with one field and 4 report counts would pass the check but crash the kernel with a NULL pointer dereference in hid_betopff_play().

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53026 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix ib block iterator counter overflow When registering a new DMA MR after selecting the best aligned page size for it, we iterate over the given sglist to split each entry to smaller, aligned to the selected page size, DMA blocks. In given circumstances where the sg entry and page size fit certain sizes and the sg entry is not aligned to the selected page size, the total size of the aligned pages we need to cover the sg entry is >= 4GB. Under this circumstances, while iterating page aligned blocks, the counter responsible for counting how much we advanced from the start of the sg entry is overflowed because its type is u32 and we pass 4GB in size. This can lead to an infinite loop inside the iterator function because the overflow prevents the counter to be larger than the size of the sg entry. Fix the presented problem by changing the advancement condition to eliminate overflow. Backtrace: [ 192.374329] efa_reg_user_mr_dmabuf [ 192.376783] efa_register_mr [ 192.382579] pgsz_bitmap 0xfffff000 rounddown 0x80000000 [ 192.386423] pg_sz [0x80000000] umem_length[0xc0000000] [ 192.392657] start 0x0 length 0xc0000000 params.page_shift 31 params.page_num 3 [ 192.399559] hp_cnt[3], pages_in_hp[524288] [ 192.403690] umem->sgt_append.sgt.nents[1] [ 192.407905] number entries: [1], pg_bit: [31] [ 192.411397] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8] [ 192.415601] biter->__sg_advance [665837568] sg_dma_len[3221225472] [ 192.419823] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8] [ 192.423976] biter->__sg_advance [2813321216] sg_dma_len[3221225472] [ 192.428243] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8] [ 192.432397] biter->__sg_advance [665837568] sg_dma_len[3221225472]

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53639 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: reduce WARN to dev_dbg() in callback The warn is triggered on a known race condition, documented in the code above the test, that is correctly handled. Using WARN() hinders automated testing. Reducing severity.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53811 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Cap MSIX used to online CPUs + 1 The irdma driver can use a maximum number of msix vectors equal to num_online_cpus() + 1 and the kernel warning stack below is shown if that number is exceeded. The kernel throws a warning as the driver tries to update the affinity hint with a CPU mask greater than the max CPU IDs. Fix this by capping the MSIX vectors to num_online_cpus() + 1. WARNING: CPU: 7 PID: 23655 at include/linux/cpumask.h:106 irdma_cfg_ceq_vector+0x34c/0x3f0 [irdma] RIP: 0010:irdma_cfg_ceq_vector+0x34c/0x3f0 [irdma] Call Trace: irdma_rt_init_hw+0xa62/0x1290 [irdma] ? irdma_alloc_local_mac_entry+0x1a0/0x1a0 [irdma] ? __is_kernel_percpu_address+0x63/0x310 ? rcu_read_lock_held_common+0xe/0xb0 ? irdma_lan_unregister_qset+0x280/0x280 [irdma] ? irdma_request_reset+0x80/0x80 [irdma] ? ice_get_qos_params+0x84/0x390 [ice] irdma_probe+0xa40/0xfc0 [irdma] ? rcu_read_lock_bh_held+0xd0/0xd0 ? irdma_remove+0x140/0x140 [irdma] ? rcu_read_lock_sched_held+0x62/0xe0 ? down_write+0x187/0x3d0 ? auxiliary_match_id+0xf0/0x1a0 ? irdma_remove+0x140/0x140 [irdma] auxiliary_bus_probe+0xa6/0x100 __driver_probe_device+0x4a4/0xd50 ? __device_attach_driver+0x2c0/0x2c0 driver_probe_device+0x4a/0x110 __driver_attach+0x1aa/0x350 bus_for_each_dev+0x11d/0x1b0 ? subsys_dev_iter_init+0xe0/0xe0 bus_add_driver+0x3b1/0x610 driver_register+0x18e/0x410 ? 0xffffffffc0b88000 irdma_init_module+0x50/0xaa [irdma] do_one_initcall+0x103/0x5f0 ? perf_trace_initcall_level+0x420/0x420 ? do_init_module+0x4e/0x700 ? __kasan_kmalloc+0x7d/0xa0 ? kmem_cache_alloc_trace+0x188/0x2b0 ? kasan_unpoison+0x21/0x50 do_init_module+0x1d1/0x700 load_module+0x3867/0x5260 ? layout_and_allocate+0x3990/0x3990 ? rcu_read_lock_held_common+0xe/0xb0 ? rcu_read_lock_sched_held+0x62/0xe0 ? rcu_read_lock_bh_held+0xd0/0xd0 ? __vmalloc_node_range+0x46b/0x890 ? lock_release+0x5c8/0xba0 ? alloc_vm_area+0x120/0x120 ? selinux_kernel_module_from_file+0x2a5/0x300 ? __inode_security_revalidate+0xf0/0xf0 ? __do_sys_init_module+0x1db/0x260 __do_sys_init_module+0x1db/0x260 ? load_module+0x5260/0x5260 ? do_syscall_64+0x22/0x450 do_syscall_64+0xa5/0x450 entry_SYSCALL_64_after_hwframe+0x66/0xdb

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53832 In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref in raid10_sync_request init_resync() inits mempool and sets conf->have_replacemnt at the beginning of sync, close_sync() frees the mempool when sync is completed. After [1] recovery might be skipped and init_resync() is called but close_sync() is not. null-ptr-deref occurs with r10bio->dev[i].repl_bio. The following is one way to reproduce the issue. 1) create a array, wait for resync to complete, mddev->recovery_cp is set to MaxSector. 2) recovery is woken and it is skipped. conf->have_replacement is set to 0 in init_resync(). close_sync() not called. 3) some io errors and rdev A is set to WantReplacement. 4) a new device is added and set to A's replacement. 5) recovery is woken, A have replacement, but conf->have_replacemnt is 0. r10bio->dev[i].repl_bio will not be alloced and null-ptr-deref occurs. Fix it by not calling init_resync() if recovery skipped. [1] commit 7e83ccbecd60 ("md/raid10: Allow skipping recovery when clean arrays are assembled")

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53844 In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Don't leak a resource on swapout move error If moving the bo to system for swapout failed, we were leaking a resource. Fix.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53847 In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Fix uninit-value in alauda_check_media() Syzbot got KMSAN to complain about access to an uninitialized value in the alauda subdriver of usb-storage: BUG: KMSAN: uninit-value in alauda_transport+0x462/0x57f0 drivers/usb/storage/alauda.c:1137 CPU: 0 PID: 12279 Comm: usb-storage Not tainted 5.3.0-rc7+ #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x191/0x1f0 lib/dump_stack.c:113 kmsan_report+0x13a/0x2b0 mm/kmsan/kmsan_report.c:108 __msan_warning+0x73/0xe0 mm/kmsan/kmsan_instr.c:250 alauda_check_media+0x344/0x3310 drivers/usb/storage/alauda.c:460 The problem is that alauda_check_media() doesn't verify that its USB transfer succeeded before trying to use the received data. What should happen if the transfer fails isn't entirely clear, but a reasonably conservative approach is to pretend that no media is present. A similar problem exists in a usb_stor_dbg() call in alauda_get_media_status(). In this case, when an error occurs the call is redundant, because usb_stor_ctrl_transfer() already will print a debugging message. Finally, unrelated to the uninitialized memory access, is the fact that alauda_check_media() performs DMA to a buffer on the stack. Fortunately usb-storage provides a general purpose DMA-able buffer for uses like this. We'll use it instead.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53848 In the Linux kernel, the following vulnerability has been resolved: md/raid5-cache: fix a deadlock in r5l_exit_log() Commit b13015af94cf ("md/raid5-cache: Clear conf->log after finishing work") introduce a new problem: // caller hold reconfig_mutex r5l_exit_log flush_work(&log->disable_writeback_work) r5c_disable_writeback_async wait_event /* * conf->log is not NULL, and mddev_trylock() * will fail, wait_event() can never pass. */ conf->log = NULL Fix this problem by setting 'config->log' to NULL before wake_up() as it used to be, so that wait_event() from r5c_disable_writeback_async() can exist. In the meantime, move forward md_unregister_thread() so that null-ptr-deref this commit fixed can still be fixed.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-53999 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Fix internal port memory leak The flow rule can be splited, and the extra post_act rules are added to post_act table. It's possible to trigger memleak when the rule forwards packets from internal port and over tunnel, in the case that, for example, CT 'new' state offload is allowed. As int_port object is assigned to the flow attribute of post_act rule, and its refcnt is incremented by mlx5e_tc_int_port_get(), but mlx5e_tc_int_port_put() is not called, the refcnt is never decremented, then int_port is never freed. The kmemleak reports the following error: unreferenced object 0xffff888128204b80 (size 64): comm "handler20", pid 50121, jiffies 4296973009 (age 642.932s) hex dump (first 32 bytes): 01 00 00 00 19 00 00 00 03 f0 00 00 04 00 00 00 ................ 98 77 67 41 81 88 ff ff 98 77 67 41 81 88 ff ff .wgA.....wgA.... backtrace: [<00000000e992680d>] kmalloc_trace+0x27/0x120 [<000000009e945a98>] mlx5e_tc_int_port_get+0x3f3/0xe20 [mlx5_core] [<0000000035a537f0>] mlx5e_tc_add_fdb_flow+0x473/0xcf0 [mlx5_core] [<0000000070c2cec6>] __mlx5e_add_fdb_flow+0x7cf/0xe90 [mlx5_core] [<000000005cc84048>] mlx5e_configure_flower+0xd40/0x4c40 [mlx5_core] [<000000004f8a2031>] mlx5e_rep_indr_offload.isra.0+0x10e/0x1c0 [mlx5_core] [<000000007df797dc>] mlx5e_rep_indr_setup_tc_cb+0x90/0x130 [mlx5_core] [<0000000016c15cc3>] tc_setup_cb_add+0x1cf/0x410 [<00000000a63305b4>] fl_hw_replace_filter+0x38f/0x670 [cls_flower] [<000000008bc9e77c>] fl_change+0x1fd5/0x4430 [cls_flower] [<00000000e7f766e4>] tc_new_tfilter+0x867/0x2010 [<00000000e101c0ef>] rtnetlink_rcv_msg+0x6fc/0x9f0 [<00000000e1111d44>] netlink_rcv_skb+0x12c/0x360 [<0000000082dd6c8b>] netlink_unicast+0x438/0x710 [<00000000fc568f70>] netlink_sendmsg+0x794/0xc50 [<0000000016e92590>] sock_sendmsg+0xc5/0x190 So fix this by moving int_port cleanup code to the flow attribute free helper, which is used by all the attribute free cases.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-54040 In the Linux kernel, the following vulnerability has been resolved: ice: fix wrong fallback logic for FDIR When adding a FDIR filter, if ice_vc_fdir_set_irq_ctx returns failure, the inserted fdir entry will not be removed and if ice_vc_fdir_write_fltr returns failure, the fdir context info for irq handler will not be cleared which may lead to inconsistent or memory leak issue. This patch refines failure cases to resolve this issue.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-54238 In the Linux kernel, the following vulnerability has been resolved: mlx5: fix skb leak while fifo resync and push During ptp resync operation SKBs were poped from the fifo but were never freed neither by napi_consume nor by dev_kfree_skb_any. Add call to napi_consume_skb to properly free SKBs. Another leak was happening because mlx5e_skb_fifo_has_room() had an error in the check. Comparing free running counters works well unless C promotes the types to something wider than the counter. In this case counters are u16 but the result of the substraction is promouted to int and it causes wrong result (negative value) of the check when producer have already overlapped but consumer haven't yet. Explicit cast to u16 fixes the issue.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2023-54285 In the Linux kernel, the following vulnerability has been resolved: iomap: Fix possible overflow condition in iomap_write_delalloc_scan folio_next_index() returns an unsigned long value which left shifted by PAGE_SHIFT could possibly cause an overflow on 32-bit system. Instead use folio_pos(folio) + folio_size(folio), which does this correctly.

nim-meta-llama3.3-70b-instruct-v2.0.3
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v2.0.3

CVE-2024-23334 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2024-23829 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input. Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2024-26130 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-7.3.2.0
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-airflow-api-server-7.3.2.0
dex-airflow-connections-7.1.9.1078
dex-airflow-connections-7.3.1.709
dex-airflow-connections-7.3.2.0
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-runtime-airflow-python-builder-7.3.2.0
hue

CVE-2024-27306 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2024-30172 An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.

thunderhead-backupjob
thunderhead-compute-api
thunderhead-configtemplate
thunderhead-consoleauthenticationcdp
thunderhead-de-api
thunderhead-deletebackupjob
thunderhead-diagnostics-api
thunderhead-drscp-api
thunderhead-dw-api
thunderhead-environment
thunderhead-environments2-api
thunderhead-hybrid
thunderhead-hybrid-api
thunderhead-iam-api
thunderhead-kerberosmgmt-api
thunderhead-ml-api
thunderhead-mlopsgovernance
thunderhead-notification
thunderhead-notification-api
thunderhead-onpremises-api
thunderhead-remotecluster
thunderhead-restorejob
thunderhead-sdx2-api
thunderhead-servicediscovery-api
thunderhead-servicediscoverysimple
thunderhead-usermanagement-private
thunderhead-userpreference
thunderhead-userpreference-api

CVE-2024-31033 JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class. NOTE: the vendor disputes this because the "ignores" behavior cannot occur (in any version) unless there is a user error in how JJWT is used, and because the version that was actually tested must have been more than six years out of date.

dmx-app

CVE-2024-38827 The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

cdc-profilers
cdc_profilers
dex-airflow-7.3.1.709
dex-airflow-api-server-7.3.1.709
dex-livy-runtime-3.5.4-7.3.1.709
dex-livy-runtime-3.5.4-7.3.2.0
dex-livy-server-3.5.4-7.3.1.709
dex-livy-server-3.5.4-7.3.2.0
dex-runtime-airflow-python-builder-7.3.1.709
dex-spark-history-server-3.5.4-7.3.1.709
dex-spark-runtime-3.5.4-7.3.1.709

CVE-2024-38949 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

ml-runtime-pbj-workbench-r4.5-standard

CVE-2024-38950 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2024-42367 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root directory if those variants are symbolic links. The server protects static routes from path traversal outside the root directory when `follow_symlinks=False` (default). It does this by resolving the requested URL to an absolute path and then checking that path relative to the root. However, these checks are not performed when looking for compressed variants in the `FileResponse` class, and symbolic links are then automatically followed when performing the `Path.stat()` and `Path.open()` to send the file. Version 3.10.2 contains a patch for the issue.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2024-52303 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError. This was caused by adding an entry to a cache on each request, due to the building of each MatchInfoError producing a unique cache entry. An attacker may be able to exhaust the memory resources of a server by sending a substantial number (100,000s to millions) of such requests. Those who use any middlewares with aiohttp.web should upgrade to version 3.10.11 to receive a patch.

nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1

CVE-2024-53177 In the Linux kernel, the following vulnerability has been resolved: smb: prevent use-after-free due to open_cached_dir error paths If open_cached_dir() encounters an error parsing the lease from the server, the error handling may race with receiving a lease break, resulting in open_cached_dir() freeing the cfid while the queued work is pending. Update open_cached_dir() to drop refs rather than directly freeing the cfid. Have cached_dir_lease_break(), cfids_laundromat_worker(), and invalidate_all_cached_dirs() clear has_lease immediately while still holding cfids->cfid_list_lock, and then use this to also simplify the reference counting in cfids_laundromat_worker() and invalidate_all_cached_dirs(). Fixes this KASAN splat (which manually injects an error and lease break in open_cached_dir()): ================================================================== BUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0 Read of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65 CPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 Workqueue: cifsiod smb2_cached_lease_break Call Trace: <TASK> dump_stack_lvl+0x77/0xb0 print_report+0xce/0x660 kasan_report+0xd3/0x110 smb2_cached_lease_break+0x27/0xb0 process_one_work+0x50a/0xc50 worker_thread+0x2ba/0x530 kthread+0x17c/0x1c0 ret_from_fork+0x34/0x60 ret_from_fork_asm+0x1a/0x30 </TASK> Allocated by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 open_cached_dir+0xa7d/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x51/0x70 kfree+0x174/0x520 open_cached_dir+0x97f/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e Last potentially related work creation: kasan_save_stack+0x33/0x60 __kasan_record_aux_stack+0xad/0xc0 insert_work+0x32/0x100 __queue_work+0x5c9/0x870 queue_work_on+0x82/0x90 open_cached_dir+0x1369/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The buggy address belongs to the object at ffff88811cc24c00 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 16 bytes inside of freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)

nim-meta-llama3.3-70b-instruct-v2.0.3
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v2.0.3

CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2025-10911 A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

runtimedataviz

CVE-2025-15661 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2025-21751 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, change error flow on matcher disconnect Currently, when firmware failure occurs during matcher disconnect flow, the error flow of the function reconnects the matcher back and returns an error, which continues running the calling function and eventually frees the matcher that is being disconnected. This leads to a case where we have a freed matcher on the matchers list, which in turn leads to use-after-free and eventual crash. This patch fixes that by not trying to reconnect the matcher back when some FW command fails during disconnect. Note that we're dealing here with FW error. We can't overcome this problem. This might lead to bad steering state (e.g. wrong connection between matchers), and will also lead to resource leakage, as it is the case with any other error handling during resource destruction. However, the goal here is to allow the driver to continue and not crash the machine with use-after-free error.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38082 In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix potential out-of-bound write If the caller wrote more characters, count is truncated to the max available space in "simple_write_to_buffer". Check that the input size does not exceed the buffer size. Write a zero termination afterwards.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38091 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to get plane_id [Why & How] Fix a false positive warning which occurs due to lack of correct checks when querying plane_id in DML21. This fixes the warning when performing a mode1 reset (cat /sys/kernel/debug/dri/1/amdgpu_gpu_recover): [ 35.751250] WARNING: CPU: 11 PID: 326 at /tmp/amd.PHpyAl7v/amd/amdgpu/../display/dc/dml2/dml2_dc_resource_mgmt.c:91 dml2_map_dc_pipes+0x243d/0x3f40 [amdgpu] [ 35.751434] Modules linked in: amdgpu(OE) amddrm_ttm_helper(OE) amdttm(OE) amddrm_buddy(OE) amdxcp(OE) amddrm_exec(OE) amd_sched(OE) amdkcl(OE) drm_suballoc_helper drm_ttm_helper ttm drm_display_helper cec rc_core i2c_algo_bit rfcomm qrtr cmac algif_hash algif_skcipher af_alg bnep amd_atl intel_rapl_msr intel_rapl_common snd_hda_codec_hdmi snd_hda_intel edac_mce_amd snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec kvm_amd snd_hda_core snd_hwdep snd_pcm kvm snd_seq_midi snd_seq_midi_event snd_rawmidi crct10dif_pclmul polyval_clmulni polyval_generic btusb ghash_clmulni_intel sha256_ssse3 btrtl sha1_ssse3 snd_seq btintel aesni_intel btbcm btmtk snd_seq_device crypto_simd sunrpc cryptd bluetooth snd_timer ccp binfmt_misc rapl snd i2c_piix4 wmi_bmof gigabyte_wmi k10temp i2c_smbus soundcore gpio_amdpt mac_hid sch_fq_codel msr parport_pc ppdev lp parport efi_pstore nfnetlink dmi_sysfs ip_tables x_tables autofs4 hid_generic usbhid hid crc32_pclmul igc ahci xhci_pci libahci xhci_pci_renesas video wmi [ 35.751501] CPU: 11 UID: 0 PID: 326 Comm: kworker/u64:9 Tainted: G OE 6.11.0-21-generic #21~24.04.1-Ubuntu [ 35.751504] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE [ 35.751505] Hardware name: Gigabyte Technology Co., Ltd. X670E AORUS PRO X/X670E AORUS PRO X, BIOS F30 05/22/2024 [ 35.751506] Workqueue: amdgpu-reset-dev amdgpu_debugfs_reset_work [amdgpu] [ 35.751638] RIP: 0010:dml2_map_dc_pipes+0x243d/0x3f40 [amdgpu] [ 35.751794] Code: 6d 0c 00 00 8b 84 24 88 00 00 00 41 3b 44 9c 20 0f 84 fc 07 00 00 48 83 c3 01 48 83 fb 06 75 b3 4c 8b 64 24 68 4c 8b 6c 24 40 <0f> 0b b8 06 00 00 00 49 8b 94 24 a0 49 00 00 89 c3 83 f8 07 0f 87 [ 35.751796] RSP: 0018:ffffbfa3805d7680 EFLAGS: 00010246 [ 35.751798] RAX: 0000000000010000 RBX: 0000000000000006 RCX: 0000000000000000 [ 35.751799] RDX: 0000000000000000 RSI: 0000000000000005 RDI: 0000000000000000 [ 35.751800] RBP: ffffbfa3805d78f0 R08: 0000000000000000 R09: 0000000000000000 [ 35.751801] R10: 0000000000000000 R11: 0000000000000000 R12: ffffbfa383249000 [ 35.751802] R13: ffffa0e68f280000 R14: ffffbfa383249658 R15: 0000000000000000 [ 35.751803] FS: 0000000000000000(0000) GS:ffffa0edbe580000(0000) knlGS:0000000000000000 [ 35.751804] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 35.751805] CR2: 00005d847ef96c58 CR3: 000000041de3e000 CR4: 0000000000f50ef0 [ 35.751806] PKRU: 55555554 [ 35.751807] Call Trace: [ 35.751810] <TASK> [ 35.751816] ? show_regs+0x6c/0x80 [ 35.751820] ? __warn+0x88/0x140 [ 35.751822] ? dml2_map_dc_pipes+0x243d/0x3f40 [amdgpu] [ 35.751964] ? report_bug+0x182/0x1b0 [ 35.751969] ? handle_bug+0x6e/0xb0 [ 35.751972] ? exc_invalid_op+0x18/0x80 [ 35.751974] ? asm_exc_invalid_op+0x1b/0x20 [ 35.751978] ? dml2_map_dc_pipes+0x243d/0x3f40 [amdgpu] [ 35.752117] ? math_pow+0x48/0xa0 [amdgpu] [ 35.752256] ? srso_alias_return_thunk+0x5/0xfbef5 [ 35.752260] ? math_pow+0x48/0xa0 [amdgpu] [ 35.752400] ? srso_alias_return_thunk+0x5/0xfbef5 [ 35.752403] ? math_pow+0x11/0xa0 [amdgpu] [ 35.752524] ? srso_alias_return_thunk+0x5/0xfbef5 [ 35.752526] ? core_dcn4_mode_programming+0xe4d/0x20d0 [amdgpu] [ 35.752663] ? srso_alias_return_thunk+0x5/0xfbef5 [ 35.752669] dml21_validate+0x3d4/0x980 [amdgpu] (cherry picked from commit f8ad62c0a93e5dd94243e10f1b742232e4d6411e)

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38486 In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel_map api support" This reverts commit 7796c97df6b1b2206681a07f3c80f6023a6593d5. This patch broke Dragonboard 845c (sdm845). I see: Unexpected kernel BRK exception at EL1 Internal error: BRK handler: 00000000f20003e8 [#1] SMP pc : qcom_swrm_set_channel_map+0x7c/0x80 [soundwire_qcom] lr : snd_soc_dai_set_channel_map+0x34/0x78 Call trace: qcom_swrm_set_channel_map+0x7c/0x80 [soundwire_qcom] (P) sdm845_dai_init+0x18c/0x2e0 [snd_soc_sdm845] snd_soc_link_init+0x28/0x6c snd_soc_bind_card+0x5f4/0xb0c snd_soc_register_card+0x148/0x1a4 devm_snd_soc_register_card+0x50/0xb0 sdm845_snd_platform_probe+0x124/0x148 [snd_soc_sdm845] platform_probe+0x6c/0xd0 really_probe+0xc0/0x2a4 __driver_probe_device+0x7c/0x130 driver_probe_device+0x40/0x118 __device_attach_driver+0xc4/0x108 bus_for_each_drv+0x8c/0xf0 __device_attach+0xa4/0x198 device_initial_probe+0x18/0x28 bus_probe_device+0xb8/0xbc deferred_probe_work_func+0xac/0xfc process_one_work+0x244/0x658 worker_thread+0x1b4/0x360 kthread+0x148/0x228 ret_from_fork+0x10/0x20 Kernel panic - not syncing: BRK handler: Fatal exception Dan has also reported following issues with the original patch https://lore.kernel.org/all/33fe8fe7-719a-405a-9ed2-d9f816ce1d57@sabinyo.mountain/ Bug #1: The zeroeth element of ctrl->pconfig[] is supposed to be unused. We start counting at 1. However this code sets ctrl->pconfig[0].ch_mask = 128. Bug #2: There are SLIM_MAX_TX_PORTS (16) elements in tx_ch[] array but only QCOM_SDW_MAX_PORTS + 1 (15) in the ctrl->pconfig[] array so it corrupts memory like Yongqin Liu pointed out. Bug 3: Like Jie Gan pointed out, it erases all the tx information with the rx information.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38553 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

dex-runtime-python-builder-7.1.9.1078-compat
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4

CVE-2025-38669 In the Linux kernel, the following vulnerability has been resolved: Revert "drm/gem-shmem: Use dma_buf from GEM object instance" This reverts commit 1a148af06000e545e714fe3210af3d77ff903c11. The dma_buf field in struct drm_gem_object is not stable over the object instance's lifetime. The field becomes NULL when user space releases the final GEM handle on the buffer object. This resulted in a NULL-pointer deref. Workarounds in commit 5307dce878d4 ("drm/gem: Acquire references on GEM handles for framebuffers") and commit f6bfc9afc751 ("drm/framebuffer: Acquire internal references on GEM handles") only solved the problem partially. They especially don't work for buffer objects without a DRM framebuffer associated. Hence, this revert to going back to using .import_attach->dmabuf. v3: - cc stable

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38672 In the Linux kernel, the following vulnerability has been resolved: Revert "drm/gem-dma: Use dma_buf from GEM object instance" This reverts commit e8afa1557f4f963c9a511bd2c6074a941c308685. The dma_buf field in struct drm_gem_object is not stable over the object instance's lifetime. The field becomes NULL when user space releases the final GEM handle on the buffer object. This resulted in a NULL-pointer deref. Workarounds in commit 5307dce878d4 ("drm/gem: Acquire references on GEM handles for framebuffers") and commit f6bfc9afc751 ("drm/framebuffer: Acquire internal references on GEM handles") only solved the problem partially. They especially don't work for buffer objects without a DRM framebuffer associated. Hence, this revert to going back to using .import_attach->dmabuf. v3: - cc stable

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38673 In the Linux kernel, the following vulnerability has been resolved: Revert "drm/gem-framebuffer: Use dma_buf from GEM object instance" This reverts commit cce16fcd7446dcff7480cd9d2b6417075ed81065. The dma_buf field in struct drm_gem_object is not stable over the object instance's lifetime. The field becomes NULL when user space releases the final GEM handle on the buffer object. This resulted in a NULL-pointer deref. Workarounds in commit 5307dce878d4 ("drm/gem: Acquire references on GEM handles for framebuffers") and commit f6bfc9afc751 ("drm/framebuffer: Acquire internal references on GEM handles") only solved the problem partially. They especially don't work for buffer objects without a DRM framebuffer associated. Hence, this revert to going back to using .import_attach->dmabuf. v3: - cc stable

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38674 In the Linux kernel, the following vulnerability has been resolved: Revert "drm/prime: Use dma_buf from GEM object instance" This reverts commit f83a9b8c7fd0557b0c50784bfdc1bbe9140c9bf8. The dma_buf field in struct drm_gem_object is not stable over the object instance's lifetime. The field becomes NULL when user space releases the final GEM handle on the buffer object. This resulted in a NULL-pointer deref. Workarounds in commit 5307dce878d4 ("drm/gem: Acquire references on GEM handles for framebuffers") and commit f6bfc9afc751 ("drm/framebuffer: Acquire internal references on GEM handles") only solved the problem partially. They especially don't work for buffer objects without a DRM framebuffer associated. Hence, this revert to going back to using .import_attach->dmabuf. v3: - cc stable

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-38689 In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Fix NULL dereference in avx512_status() Problem ------- With CONFIG_X86_DEBUG_FPU enabled, reading /proc/[kthread]/arch_status causes a warning and a NULL pointer dereference. This is because the AVX-512 timestamp code uses x86_task_fpu() but doesn't check it for NULL. CONFIG_X86_DEBUG_FPU addles that function for kernel threads (PF_KTHREAD specifically), making it return NULL. The point of the warning was to ensure that kernel threads only access task->fpu after going through kernel_fpu_begin()/_end(). Note: all kernel tasks exposed in /proc have a valid task->fpu. Solution -------- One option is to silence the warning and check for NULL from x86_task_fpu(). However, that warning is fairly fresh and seems like a defense against misuse of the FPU state in kernel threads. Instead, stop outputting AVX-512_elapsed_ms for kernel threads altogether. The data was garbage anyway because avx512_timestamp is only updated for user threads, not kernel threads. If anyone ever wants to track kernel thread AVX-512 use, they can come back later and do it properly, separate from this bug fix. [ dhansen: mostly rewrite changelog ]

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-40222 In the Linux kernel, the following vulnerability has been resolved: tty: serial: sh-sci: fix RSCI FIFO overrun handling The receive error handling code is shared between RSCI and all other SCIF port types, but the RSCI overrun_reg is specified as a memory offset, while for other SCIF types it is an enum value used to index into the sci_port_params->regs array, as mentioned above the sci_serial_in() function. For RSCI, the overrun_reg is CSR (0x48), causing the sci_getreg() call inside the sci_handle_fifo_overrun() function to index outside the bounds of the regs array, which currently has a size of 20, as specified by SCI_NR_REGS. Because of this, we end up accessing memory outside of RSCI's rsci_port_params structure, which, when interpreted as a plat_sci_reg, happens to have a non-zero size, causing the following WARN when sci_serial_in() is called, as the accidental size does not match the supported register sizes. The existence of the overrun_reg needs to be checked because SCIx_SH3_SCIF_REGTYPE has overrun_reg set to SCLSR, but SCLSR is not present in the regs array. Avoid calling sci_getreg() for port types which don't use standard register handling. Use the ops->read_reg() and ops->write_reg() functions to properly read and write registers for RSCI, and change the type of the status variable to accommodate the 32-bit CSR register. sci_getreg() and sci_serial_in() are also called with overrun_reg in the sci_mpxed_interrupt() interrupt handler, but that code path is not used for RSCI, as it does not have a muxed interrupt. ------------[ cut here ]------------ Invalid register access WARNING: CPU: 0 PID: 0 at drivers/tty/serial/sh-sci.c:522 sci_serial_in+0x38/0xac Modules linked in: renesas_usbhs at24 rzt2h_adc industrialio_adc sha256 cfg80211 bluetooth ecdh_generic ecc rfkill fuse drm backlight ipv6 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.17.0-rc1+ #30 PREEMPT Hardware name: Renesas RZ/T2H EVK Board based on r9a09g077m44 (DT) pstate: 604000c5 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : sci_serial_in+0x38/0xac lr : sci_serial_in+0x38/0xac sp : ffff800080003e80 x29: ffff800080003e80 x28: ffff800082195b80 x27: 000000000000000d x26: ffff8000821956d0 x25: 0000000000000000 x24: ffff800082195b80 x23: ffff000180e0d800 x22: 0000000000000010 x21: 0000000000000000 x20: 0000000000000010 x19: ffff000180e72000 x18: 000000000000000a x17: ffff8002bcee7000 x16: ffff800080000000 x15: 0720072007200720 x14: 0720072007200720 x13: 0720072007200720 x12: 0720072007200720 x11: 0000000000000058 x10: 0000000000000018 x9 : ffff8000821a6a48 x8 : 0000000000057fa8 x7 : 0000000000000406 x6 : ffff8000821fea48 x5 : ffff00033ef88408 x4 : ffff8002bcee7000 x3 : ffff800082195b80 x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff800082195b80 Call trace: sci_serial_in+0x38/0xac (P) sci_handle_fifo_overrun.isra.0+0x70/0x134 sci_er_interrupt+0x50/0x39c __handle_irq_event_percpu+0x48/0x140 handle_irq_event+0x44/0xb0 handle_fasteoi_irq+0xf4/0x1a0 handle_irq_desc+0x34/0x58 generic_handle_domain_irq+0x1c/0x28 gic_handle_irq+0x4c/0x140 call_on_irq_stack+0x30/0x48 do_interrupt_handler+0x80/0x84 el1_interrupt+0x34/0x68 el1h_64_irq_handler+0x18/0x24 el1h_64_irq+0x6c/0x70 default_idle_call+0x28/0x58 (P) do_idle+0x1f8/0x250 cpu_startup_entry+0x34/0x3c rest_init+0xd8/0xe0 console_on_rootfs+0x0/0x6c __primary_switched+0x88/0x90 ---[ end trace 0000000000000000 ]---

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-50817 A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

cdwdataviz
dex-airflow-7.1.9.1078
dex-airflow-7.3.1.709
dex-airflow-7.3.2.0
dex-airflow-api-server-7.1.9.1078
dex-airflow-api-server-7.3.1.709
dex-airflow-api-server-7.3.2.0
dex-runtime-airflow-python-builder-7.1.9.1078
dex-runtime-airflow-python-builder-7.3.1.709
dex-runtime-airflow-python-builder-7.3.2.0
hue
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
runtimedataviz

CVE-2025-61147 strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

ml-runtime-pbj-workbench-r4.5-standard

CVE-2025-66506 Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This vulnerability is fixed in 1.8.3.

cdsw-s2i-builder-buildah

CVE-2025-68368 In the Linux kernel, the following vulnerability has been resolved: md: init bioset in mddev_init IO operations may be needed before md_run(), such as updating metadata after writing sysfs. Without bioset, this triggers a NULL pointer dereference as below: BUG: kernel NULL pointer dereference, address: 0000000000000020 Call Trace: md_update_sb+0x658/0xe00 new_level_store+0xc5/0x120 md_attr_store+0xc9/0x1e0 sysfs_kf_write+0x6f/0xa0 kernfs_fop_write_iter+0x141/0x2a0 vfs_write+0x1fc/0x5a0 ksys_write+0x79/0x180 __x64_sys_write+0x1d/0x30 x64_sys_call+0x2818/0x2880 do_syscall_64+0xa9/0x580 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Reproducer ``` mdadm -CR /dev/md0 -l1 -n2 /dev/sd[cd] echo inactive > /sys/block/md0/md/array_state echo 10 > /sys/block/md0/md/new_level ``` mddev_init() can only be called once per mddev, no need to test if bioset has been initialized anymore.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68779 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid unregistering PSP twice PSP is unregistered twice in: _mlx5e_remove -> mlx5e_psp_unregister mlx5e_nic_cleanup -> mlx5e_psp_unregister This leads to a refcount underflow in some conditions: ------------[ cut here ]------------ refcount_t: underflow; use-after-free. WARNING: CPU: 2 PID: 1694 at lib/refcount.c:28 refcount_warn_saturate+0xd8/0xe0 [...] mlx5e_psp_unregister+0x26/0x50 [mlx5_core] mlx5e_nic_cleanup+0x26/0x90 [mlx5_core] mlx5e_remove+0xe6/0x1f0 [mlx5_core] auxiliary_bus_remove+0x18/0x30 device_release_driver_internal+0x194/0x1f0 bus_remove_device+0xc6/0x130 device_del+0x159/0x3c0 mlx5_rescan_drivers_locked+0xbc/0x2a0 [mlx5_core] [...] Do not directly remove psp from the _mlx5e_remove path, the PSP cleanup happens as part of profile cleanup.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2025-68784 In the Linux kernel, the following vulnerability has been resolved: xfs: fix a UAF problem in xattr repair The xchk_setup_xattr_buf function can allocate a new value buffer, which means that any reference to ab->value before the call could become a dangling pointer. Fix this by moving an assignment to after the buffer setup.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68791 In the Linux kernel, the following vulnerability has been resolved: fuse: missing copy_finish in fuse-over-io-uring argument copies Fix a possible reference count leak of payload pages during fuse argument copies. [Joanne: simplified error cleanup]

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68792 In the Linux kernel, the following vulnerability has been resolved: tpm2-sessions: Fix out of range indexing in name_size 'name_size' does not have any range checks, and it just directly indexes with TPM_ALG_ID, which could lead into memory corruption at worst. Address the issue by only processing known values and returning -EINVAL for unrecognized values. Make also 'tpm_buf_append_name' and 'tpm_buf_fill_hmac_session' fallible so that errors are detected before causing any spurious TPM traffic. End also the authorization session on failure in both of the functions, as the session state would be then by definition corrupted.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68793 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix a job->pasid access race in gpu recovery Avoid a possible UAF in GPU recovery due to a race between the sched timeout callback and the tdr work queue. The gpu recovery function calls drm_sched_stop() and later drm_sched_start(). drm_sched_start() restarts the tdr queue which will eventually free the job. If the tdr queue frees the job before time out callback completes, the job will be freed and we'll get a UAF when accessing the pasid. Cache it early to avoid the UAF. Example KASAN trace: [ 493.058141] BUG: KASAN: slab-use-after-free in amdgpu_device_gpu_recover+0x968/0x990 [amdgpu] [ 493.067530] Read of size 4 at addr ffff88b0ce3f794c by task kworker/u128:1/323 [ 493.074892] [ 493.076485] CPU: 9 UID: 0 PID: 323 Comm: kworker/u128:1 Tainted: G E 6.16.0-1289896.2.zuul.bf4f11df81c1410bbe901c4373305a31 #1 PREEMPT(voluntary) [ 493.076493] Tainted: [E]=UNSIGNED_MODULE [ 493.076495] Hardware name: TYAN B8021G88V2HR-2T/S8021GM2NR-2T, BIOS V1.03.B10 04/01/2019 [ 493.076500] Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched] [ 493.076512] Call Trace: [ 493.076515] <TASK> [ 493.076518] dump_stack_lvl+0x64/0x80 [ 493.076529] print_report+0xce/0x630 [ 493.076536] ? _raw_spin_lock_irqsave+0x86/0xd0 [ 493.076541] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 493.076545] ? amdgpu_device_gpu_recover+0x968/0x990 [amdgpu] [ 493.077253] kasan_report+0xb8/0xf0 [ 493.077258] ? amdgpu_device_gpu_recover+0x968/0x990 [amdgpu] [ 493.077965] amdgpu_device_gpu_recover+0x968/0x990 [amdgpu] [ 493.078672] ? __pfx_amdgpu_device_gpu_recover+0x10/0x10 [amdgpu] [ 493.079378] ? amdgpu_coredump+0x1fd/0x4c0 [amdgpu] [ 493.080111] amdgpu_job_timedout+0x642/0x1400 [amdgpu] [ 493.080903] ? pick_task_fair+0x24e/0x330 [ 493.080910] ? __pfx_amdgpu_job_timedout+0x10/0x10 [amdgpu] [ 493.081702] ? _raw_spin_lock+0x75/0xc0 [ 493.081708] ? __pfx__raw_spin_lock+0x10/0x10 [ 493.081712] drm_sched_job_timedout+0x1b0/0x4b0 [gpu_sched] [ 493.081721] ? __pfx__raw_spin_lock_irq+0x10/0x10 [ 493.081725] process_one_work+0x679/0xff0 [ 493.081732] worker_thread+0x6ce/0xfd0 [ 493.081736] ? __pfx_worker_thread+0x10/0x10 [ 493.081739] kthread+0x376/0x730 [ 493.081744] ? __pfx_kthread+0x10/0x10 [ 493.081748] ? __pfx__raw_spin_lock_irq+0x10/0x10 [ 493.081751] ? __pfx_kthread+0x10/0x10 [ 493.081755] ret_from_fork+0x247/0x330 [ 493.081761] ? __pfx_kthread+0x10/0x10 [ 493.081764] ret_from_fork_asm+0x1a/0x30 [ 493.081771] </TASK> (cherry picked from commit 20880a3fd5dd7bca1a079534cf6596bda92e107d)

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68805 In the Linux kernel, the following vulnerability has been resolved: fuse: fix io-uring list corruption for terminated non-committed requests When a request is terminated before it has been committed, the request is not removed from the queue's list. This leaves a dangling list entry that leads to list corruption and use-after-free issues. Remove the request from the queue's list for terminated non-committed requests.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-68807 In the Linux kernel, the following vulnerability has been resolved: block: fix race between wbt_enable_default and IO submission When wbt_enable_default() is moved out of queue freezing in elevator_change(), it can cause the wbt inflight counter to become negative (-1), leading to hung tasks in the writeback path. Tasks get stuck in wbt_wait() because the counter is in an inconsistent state. The issue occurs because wbt_enable_default() could race with IO submission, allowing the counter to be decremented before proper initialization. This manifests as: rq_wait[0]: inflight: -1 has_waiters: True rwb_enabled() checks the state, which can be updated exactly between wbt_wait() (rq_qos_throttle()) and wbt_track()(rq_qos_track()), then the inflight counter will become negative. And results in hung task warnings like: task:kworker/u24:39 state:D stack:0 pid:14767 Call Trace: rq_qos_wait+0xb4/0x150 wbt_wait+0xa9/0x100 __rq_qos_throttle+0x24/0x40 blk_mq_submit_bio+0x672/0x7b0 ... Fix this by: 1. Splitting wbt_enable_default() into: - __wbt_enable_default(): Returns true if wbt_init() should be called - wbt_enable_default(): Wrapper for existing callers (no init) - wbt_init_enable_default(): New function that checks and inits WBT 2. Using wbt_init_enable_default() in blk_register_queue() to ensure proper initialization during queue registration 3. Move wbt_init() out of wbt_enable_default() which is only for enabling disabled wbt from bfq and iocost, and wbt_init() isn't needed. Then the original lock warning can be avoided. 4. Removing the ELEVATOR_FLAG_ENABLE_WBT_ON_EXIT flag and its handling code since it's no longer needed This ensures WBT is properly initialized before any IO can be submitted, preventing the counter from going negative.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-69873 ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.

cdsw-web

CVE-2025-71070 In the Linux kernel, the following vulnerability has been resolved: ublk: clean up user copy references on ublk server exit If a ublk server process releases a ublk char device file, any requests dispatched to the ublk server but not yet completed will retain a ref value of UBLK_REFCOUNT_INIT. Before commit e63d2228ef83 ("ublk: simplify aborting ublk request"), __ublk_fail_req() would decrement the reference count before completing the failed request. However, that commit optimized __ublk_fail_req() to call __ublk_complete_rq() directly without decrementing the request reference count. The leaked reference count incorrectly allows user copy and zero copy operations on the completed ublk request. It also triggers the WARN_ON_ONCE(refcount_read(&io->ref)) warnings in ublk_queue_reinit() and ublk_deinit_queue(). Commit c5c5eb24ed61 ("ublk: avoid ublk_io_release() called after ublk char dev is closed") already fixed the issue for ublk devices using UBLK_F_SUPPORT_ZERO_COPY or UBLK_F_AUTO_BUF_REG. However, the reference count leak also affects UBLK_F_USER_COPY, the other reference-counted data copy mode. Fix the condition in ublk_check_and_reset_active_ref() to include all reference-counted data copy modes. This ensures that any ublk requests still owned by the ublk server when it exits have their reference counts reset to 0.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71076 In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Limit num_syncs to prevent oversized allocations The OA open parameters did not validate num_syncs, allowing userspace to pass arbitrarily large values, potentially leading to excessive allocations. Add check to ensure that num_syncs does not exceed DRM_XE_MAX_SYNCS, returning -EINVAL when the limit is violated. v2: use XE_IOCTL_DBG() and drop duplicated check. (Ashutosh) (cherry picked from commit e057b2d2b8d815df3858a87dffafa2af37e5945b)

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71080 In the Linux kernel, the following vulnerability has been resolved: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT On PREEMPT_RT kernels, after rt6_get_pcpu_route() returns NULL, the current task can be preempted. Another task running on the same CPU may then execute rt6_make_pcpu_route() and successfully install a pcpu_rt entry. When the first task resumes execution, its cmpxchg() in rt6_make_pcpu_route() will fail because rt6i_pcpu is no longer NULL, triggering the BUG_ON(prev). It's easy to reproduce it by adding mdelay() after rt6_get_pcpu_route(). Using preempt_disable/enable is not appropriate here because ip6_rt_pcpu_alloc() may sleep. Fix this by handling the cmpxchg() failure gracefully on PREEMPT_RT: free our allocation and return the existing pcpu_rt installed by another task. The BUG_ON is replaced by WARN_ON_ONCE for non-PREEMPT_RT kernels where such races should not occur.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71090 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file reference leak in nfsd4_add_rdaccess_to_wrdeleg() nfsd4_add_rdaccess_to_wrdeleg() unconditionally overwrites fp->fi_fds[O_RDONLY] with a newly acquired nfsd_file. However, if the client already has a SHARE_ACCESS_READ open from a previous OPEN operation, this action overwrites the existing pointer without releasing its reference, orphaning the previous reference. Additionally, the function originally stored the same nfsd_file pointer in both fp->fi_fds[O_RDONLY] and fp->fi_rdeleg_file with only a single reference. When put_deleg_file() runs, it clears fi_rdeleg_file and calls nfs4_file_put_access() to release the file. However, nfs4_file_put_access() only releases fi_fds[O_RDONLY] when the fi_access[O_RDONLY] counter drops to zero. If another READ open exists on the file, the counter remains elevated and the nfsd_file reference from the delegation is never released. This potentially causes open conflicts on that file. Then, on server shutdown, these leaks cause __nfsd_file_cache_purge() to encounter files with an elevated reference count that cannot be cleaned up, ultimately triggering a BUG() in kmem_cache_destroy() because there are still nfsd_file objects allocated in that cache.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71099 In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() In xe_oa_add_config_ioctl(), we accessed oa_config->id after dropping metrics_lock. Since this lock protects the lifetime of oa_config, an attacker could guess the id and call xe_oa_remove_config_ioctl() with perfect timing, freeing oa_config before we dereference it, leading to a potential use-after-free. Fix this by caching the id in a local variable while holding the lock. v2: (Matt A) - Dropped mutex_unlock(&oa->metrics_lock) ordering change from xe_oa_remove_config_ioctl() (cherry picked from commit 28aeaed130e8e587fd1b73b6d66ca41ccc5a1a31)

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71100 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl92cu_tx_fill_desc() TID getting from ieee80211_get_tid() might be out of range of array size of sta_entry->tids[], so check TID is less than MAX_TID_COUNT. Othwerwise, UBSAN warn: UBSAN: array-index-out-of-bounds in drivers/net/wireless/realtek/rtlwifi/rtl8192cu/trx.c:514:30 index 10 is out of range for type 'rtl_tid_data [9]'

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71117 In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs store callbacks Freezing the request queue from inside sysfs store callbacks may cause a deadlock in combination with the dm-multipath driver and the queue_if_no_path option. Additionally, freezing the request queue slows down system boot on systems where sysfs attributes are set synchronously. Fix this by removing the blk_mq_freeze_queue() / blk_mq_unfreeze_queue() calls from the store callbacks that do not strictly need these callbacks. Add the __data_racy annotation to request_queue.rq_timeout to suppress KCSAN data race reports about the rq_timeout reads. This patch may cause a small delay in applying the new settings. For all the attributes affected by this patch, I/O will complete correctly whether the old or the new value of the attribute is used. This patch affects the following sysfs attributes: * io_poll_delay * io_timeout * nomerges * read_ahead_kb * rq_affinity Here is an example of a deadlock triggered by running test srp/002 if this patch is not applied: task:multipathd Call Trace: <TASK> __schedule+0x8c1/0x1bf0 schedule+0xdd/0x270 schedule_preempt_disabled+0x1c/0x30 __mutex_lock+0xb89/0x1650 mutex_lock_nested+0x1f/0x30 dm_table_set_restrictions+0x823/0xdf0 __bind+0x166/0x590 dm_swap_table+0x2a7/0x490 do_resume+0x1b1/0x610 dev_suspend+0x55/0x1a0 ctl_ioctl+0x3a5/0x7e0 dm_ctl_ioctl+0x12/0x20 __x64_sys_ioctl+0x127/0x1a0 x64_sys_call+0xe2b/0x17d0 do_syscall_64+0x96/0x3a0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> task:(udev-worker) Call Trace: <TASK> __schedule+0x8c1/0x1bf0 schedule+0xdd/0x270 blk_mq_freeze_queue_wait+0xf2/0x140 blk_mq_freeze_queue_nomemsave+0x23/0x30 queue_ra_store+0x14e/0x290 queue_attr_store+0x23e/0x2c0 sysfs_kf_write+0xde/0x140 kernfs_fop_write_iter+0x3b2/0x630 vfs_write+0x4fd/0x1390 ksys_write+0xfd/0x230 __x64_sys_write+0x76/0xc0 x64_sys_call+0x276/0x17d0 do_syscall_64+0x96/0x3a0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK>

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71124 In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: move preempt_prepare_postamble after error check Move the call to preempt_prepare_postamble() after verifying that preempt_postamble_ptr is valid. If preempt_postamble_ptr is NULL, dereferencing it in preempt_prepare_postamble() would lead to a crash. This change avoids calling the preparation function when the postamble allocation has failed, preventing potential NULL pointer dereference and ensuring proper error handling. Patchwork: https://patchwork.freedesktop.org/patch/687659/

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71134 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: change all pageblocks migrate type on coalescing When a page is freed it coalesces with a buddy into a higher order page while possible. When the buddy page migrate type differs, it is expected to be updated to match the one of the page being freed. However, only the first pageblock of the buddy page is updated, while the rest of the pageblocks are left unchanged. That causes warnings in later expand() and other code paths (like below), since an inconsistency between migration type of the list containing the page and the page-owned pageblocks migration types is introduced. [ 308.986589] ------------[ cut here ]------------ [ 308.987227] page type is 0, passed migratetype is 1 (nr=256) [ 308.987275] WARNING: CPU: 1 PID: 5224 at mm/page_alloc.c:812 expand+0x23c/0x270 [ 308.987293] Modules linked in: algif_hash(E) af_alg(E) nft_fib_inet(E) nft_fib_ipv4(E) nft_fib_ipv6(E) nft_fib(E) nft_reject_inet(E) nf_reject_ipv4(E) nf_reject_ipv6(E) nft_reject(E) nft_ct(E) nft_chain_nat(E) nf_nat(E) nf_conntrack(E) nf_defrag_ipv6(E) nf_defrag_ipv4(E) nf_tables(E) s390_trng(E) vfio_ccw(E) mdev(E) vfio_iommu_type1(E) vfio(E) sch_fq_codel(E) drm(E) i2c_core(E) drm_panel_orientation_quirks(E) loop(E) nfnetlink(E) vsock_loopback(E) vmw_vsock_virtio_transport_common(E) vsock(E) ctcm(E) fsm(E) diag288_wdt(E) watchdog(E) zfcp(E) scsi_transport_fc(E) ghash_s390(E) prng(E) aes_s390(E) des_generic(E) des_s390(E) libdes(E) sha3_512_s390(E) sha3_256_s390(E) sha_common(E) paes_s390(E) crypto_engine(E) pkey_cca(E) pkey_ep11(E) zcrypt(E) rng_core(E) pkey_pckmo(E) pkey(E) autofs4(E) [ 308.987439] Unloaded tainted modules: hmac_s390(E):2 [ 308.987650] CPU: 1 UID: 0 PID: 5224 Comm: mempig_verify Kdump: loaded Tainted: G E 6.18.0-gcc-bpf-debug #431 PREEMPT [ 308.987657] Tainted: [E]=UNSIGNED_MODULE [ 308.987661] Hardware name: IBM 3906 M04 704 (z/VM 7.3.0) [ 308.987666] Krnl PSW : 0404f00180000000 00000349976fa600 (expand+0x240/0x270) [ 308.987676] R:0 T:1 IO:0 EX:0 Key:0 M:1 W:0 P:0 AS:3 CC:3 PM:0 RI:0 EA:3 [ 308.987682] Krnl GPRS: 0000034980000004 0000000000000005 0000000000000030 000003499a0e6d88 [ 308.987688] 0000000000000005 0000034980000005 000002be803ac000 0000023efe6c8300 [ 308.987692] 0000000000000008 0000034998d57290 000002be00000100 0000023e00000008 [ 308.987696] 0000000000000000 0000000000000000 00000349976fa5fc 000002c99b1eb6f0 [ 308.987708] Krnl Code: 00000349976fa5f0: c020008a02f2 larl %r2,000003499883abd4 00000349976fa5f6: c0e5ffe3f4b5 brasl %r14,0000034997378f60 #00000349976fa5fc: af000000 mc 0,0 >00000349976fa600: a7f4ff4c brc 15,00000349976fa498 00000349976fa604: b9040026 lgr %r2,%r6 00000349976fa608: c0300088317f larl %r3,0000034998800906 00000349976fa60e: c0e5fffdb6e1 brasl %r14,00000349976b13d0 00000349976fa614: af000000 mc 0,0 [ 308.987734] Call Trace: [ 308.987738] [<00000349976fa600>] expand+0x240/0x270 [ 308.987744] ([<00000349976fa5fc>] expand+0x23c/0x270) [ 308.987749] [<00000349976ff95e>] rmqueue_bulk+0x71e/0x940 [ 308.987754] [<00000349976ffd7e>] __rmqueue_pcplist+0x1fe/0x2a0 [ 308.987759] [<0000034997700966>] rmqueue.isra.0+0xb46/0xf40 [ 308.987763] [<0000034997703ec8>] get_page_from_freelist+0x198/0x8d0 [ 308.987768] [<0000034997706fa8>] __alloc_frozen_pages_noprof+0x198/0x400 [ 308.987774] [<00000349977536f8>] alloc_pages_mpol+0xb8/0x220 [ 308.987781] [<0000034997753bf6>] folio_alloc_mpol_noprof+0x26/0xc0 [ 308.987786] [<0000034997753e4c>] vma_alloc_folio_noprof+0x6c/0xa0 [ 308.987791] [<0000034997775b22>] vma_alloc_anon_folio_pmd+0x42/0x240 [ 308.987799] [<000003499777bfea>] __do_huge_pmd_anonymous_page+0x3a/0x210 [ 308.987804] [<00000349976cb0 ---truncated---

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71139 In the Linux kernel, the following vulnerability has been resolved: kernel/kexec: fix IMA when allocation happens in CMA area *** Bug description *** When I tested kexec with the latest kernel, I ran into the following warning: [ 40.712410] ------------[ cut here ]------------ [ 40.712576] WARNING: CPU: 2 PID: 1562 at kernel/kexec_core.c:1001 kimage_map_segment+0x144/0x198 [...] [ 40.816047] Call trace: [ 40.818498] kimage_map_segment+0x144/0x198 (P) [ 40.823221] ima_kexec_post_load+0x58/0xc0 [ 40.827246] __do_sys_kexec_file_load+0x29c/0x368 [...] [ 40.855423] ---[ end trace 0000000000000000 ]--- *** How to reproduce *** This bug is only triggered when the kexec target address is allocated in the CMA area. If no CMA area is reserved in the kernel, use the "cma=" option in the kernel command line to reserve one. *** Root cause *** The commit 07d24902977e ("kexec: enable CMA based contiguous allocation") allocates the kexec target address directly on the CMA area to avoid copying during the jump. In this case, there is no IND_SOURCE for the kexec segment. But the current implementation of kimage_map_segment() assumes that IND_SOURCE pages exist and map them into a contiguous virtual address by vmap(). *** Solution *** If IMA segment is allocated in the CMA area, use its page_address() directly.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71142 In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition A warning was triggered as follows: WARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110 RIP: 0010:remote_partition_disable+0xf7/0x110 RSP: 0018:ffffc90001947d88 EFLAGS: 00000206 RAX: 0000000000007fff RBX: ffff888103b6e000 RCX: 0000000000006f40 RDX: 0000000000006f00 RSI: ffffc90001947da8 RDI: ffff888103b6e000 RBP: ffff888103b6e000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000001 R11: ffff88810b2e2728 R12: ffffc90001947da8 R13: 0000000000000000 R14: ffffc90001947da8 R15: ffff8881081f1c00 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f55c8bbe0b2 CR3: 000000010b14c000 CR4: 00000000000006f0 Call Trace: <TASK> update_prstate+0x2d3/0x580 cpuset_partition_write+0x94/0xf0 kernfs_fop_write_iter+0x147/0x200 vfs_write+0x35d/0x500 ksys_write+0x66/0xe0 do_syscall_64+0x6b/0x390 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f55c8cd4887 Reproduction steps (on a 16-CPU machine): # cd /sys/fs/cgroup/ # mkdir A1 # echo +cpuset > A1/cgroup.subtree_control # echo "0-14" > A1/cpuset.cpus.exclusive # mkdir A1/A2 # echo "0-14" > A1/A2/cpuset.cpus.exclusive # echo "root" > A1/A2/cpuset.cpus.partition # echo 0 > /sys/devices/system/cpu/cpu15/online # echo member > A1/A2/cpuset.cpus.partition When CPU 15 is offlined, subpartitions_cpus gets cleared because no CPUs remain available for the top_cpuset, forcing partitions to share CPUs with the top_cpuset. In this scenario, disabling the remote partition triggers a warning stating that effective_xcpus is not a subset of subpartitions_cpus. Partitions should be invalidated in this case to inform users that the partition is now invalid(cpus are shared with top_cpuset). To fix this issue: 1. Only emit the warning only if subpartitions_cpus is not empty and the effective_xcpus is not a subset of subpartitions_cpus. 2. During the CPU hotplug process, invalidate partitions if subpartitions_cpus is empty.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71146 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is always called.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71155 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A few checks were missing in gmap_helper_zap_one_page(), which can lead to memory corruption in the guest under specific circumstances. Add the missing checks.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71156 In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registration Currently, interrupts are automatically enabled immediately upon request. This allows interrupt to fire before the associated NAPI context is fully initialized and cause failures like below: [ 0.946369] Call Trace: [ 0.946369] <IRQ> [ 0.946369] __napi_poll+0x2a/0x1e0 [ 0.946369] net_rx_action+0x2f9/0x3f0 [ 0.946369] handle_softirqs+0xd6/0x2c0 [ 0.946369] ? handle_edge_irq+0xc1/0x1b0 [ 0.946369] __irq_exit_rcu+0xc3/0xe0 [ 0.946369] common_interrupt+0x81/0xa0 [ 0.946369] </IRQ> [ 0.946369] <TASK> [ 0.946369] asm_common_interrupt+0x22/0x40 [ 0.946369] RIP: 0010:pv_native_safe_halt+0xb/0x10 Use the `IRQF_NO_AUTOEN` flag when requesting interrupts to prevent auto enablement and explicitly enable the interrupt in NAPI initialization path (and disable it during NAPI teardown). This ensures that interrupt lifecycle is strictly coupled with readiness of NAPI context.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2025-71157 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_sub_device_and_put() Since nldev_deldev() (introduced by commit 060c642b2ab8 ("RDMA/nldev: Add support to add/delete a sub IB device through netlink") grabs a reference using ib_device_get_by_index() before calling ib_del_sub_device_and_put(), we need to drop that reference before returning -EOPNOTSUPP error.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-2359 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.

cdsw-web

CVE-2026-3304 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.

cdsw-web

CVE-2026-3520 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available.

cdsw-web

CVE-2026-3805 When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

dex-livy-runtime-2.4.8-7.1.9.1078
dex-livy-runtime-3.3.2-7.1.9.1078-compat
dex-livy-server-2.4.8-7.1.9.1078
dex-runtime-python-builder-7.1.9.1078-compat
dex-spark-history-server-2.4.8-7.1.9.1078
dex-spark-runtime-2.4.8-7.1.9.1078
dex-spark-runtime-3.3.2-7.1.9.1078-compat

CVE-2026-3902 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

cdwdataviz
runtimedataviz

CVE-2026-3950 A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-4277 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.

cdwdataviz
runtimedataviz

CVE-2026-4292 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

cdwdataviz
runtimedataviz

CVE-2026-5038 Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

cdsw-web

CVE-2026-5079 Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingDepth option to the minimum depth their application requires. Workarounds: Set limits.fields to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.

cdsw-web

CVE-2026-7598 A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-9079 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-9080 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-9545 In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-10118 A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-10881 Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10882 Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10883 Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10884 Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10886 Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10888 Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10889 Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10890 Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10891 Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10893 Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10894 Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10895 Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10897 Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10898 Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10899 Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10902 Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-10903 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10904 Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10905 Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10906 Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10907 Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10909 Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10910 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10911 Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10912 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10916 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10917 Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10918 Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10919 Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10921 Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10922 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via malicious network traffic. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10924 Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10926 Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10927 Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10928 Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10931 Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10935 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10936 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10937 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10938 Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10939 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10941 Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10943 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10945 Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10946 Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10947 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10948 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10949 Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10954 Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10956 Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10957 Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10960 Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10962 Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10963 Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10964 Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10965 Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10966 Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10969 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10970 Insufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10972 Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10973 Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10974 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10975 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10976 Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10977 Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10979 Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10980 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10981 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted video file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10982 Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10983 Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10985 Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10986 Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10987 Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10988 Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10989 Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-10990 Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10991 Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10992 Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10993 Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10994 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10995 Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10996 Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10997 Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10998 Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-10999 Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11000 Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11001 Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11002 Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11003 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11004 Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11006 Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11008 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11011 Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11013 Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11014 Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11015 Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11016 Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11017 Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11018 Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11020 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted XML file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11022 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11023 Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11024 Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11026 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11027 Insufficient validation of untrusted input in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11028 Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11030 Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11031 Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11032 Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11036 Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11037 Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11038 Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11039 Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11040 Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11042 Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11045 Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11046 Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11048 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11049 Use after free in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11050 Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11051 Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11054 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11057 Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11059 Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11061 Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11062 Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11065 Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11066 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11067 Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11068 Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11069 Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11071 Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11073 Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11074 Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11075 Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11076 Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11077 Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11078 Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11079 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11081 Inappropriate implementation in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11083 Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11084 Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11086 Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11087 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11088 Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11089 Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11090 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11091 Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11092 Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11093 Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11095 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11096 Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11098 Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11102 Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11104 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11105 Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11106 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11107 Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11109 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11110 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11111 Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11112 Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11113 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11116 Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11118 Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11120 Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11121 Insufficient validation of untrusted input in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11122 Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11123 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11124 Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11125 Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11126 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11128 Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11129 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11130 Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11132 Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11133 Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11134 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11135 Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11136 Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11137 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11138 Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11139 Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11140 Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11141 Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11142 Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11143 Out of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11144 Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11146 Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11149 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11150 Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11151 Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11152 Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11153 Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11154 Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11155 Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11156 Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11157 Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11159 Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11160 Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11161 Inappropriate implementation in DataTransfer in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11162 Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11164 Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11166 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11168 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11169 Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11170 Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11171 Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11173 Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11174 Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11176 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11177 Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11179 Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11180 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11181 Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11182 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11183 Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11184 Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11185 Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11186 Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11187 Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11189 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11190 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11191 Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11192 Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11193 Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11194 Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11195 Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11196 Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11197 Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11198 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11199 Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11200 Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11201 Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11206 Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11207 Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11208 Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11209 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11210 Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11211 Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11212 Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11213 Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11216 Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11217 Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11219 Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11220 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11221 Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11222 Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11223 Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11224 Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11225 Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11227 Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11228 Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11229 Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11230 Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11232 Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11233 Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11234 Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11235 Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11236 Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11237 Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11238 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11239 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11240 Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11241 Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11242 Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11243 Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11244 Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11245 Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11246 Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11248 Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11249 Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11250 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11251 Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11252 Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11253 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11254 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11255 Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11256 Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11257 Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11258 Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11259 Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11260 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11261 Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11262 Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11264 Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11265 Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11266 Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11267 Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11269 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11271 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11273 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11276 Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11279 Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11282 Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11284 Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11286 Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11288 Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11289 Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11292 Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11293 Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11294 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11296 Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11299 Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11300 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11301 Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11303 Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11304 Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11305 Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11306 Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11307 Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11308 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11309 Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

cdwdataviz
runtimedataviz

CVE-2026-11628 Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11629 Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11630 Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11632 Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11638 Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11640 Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11642 Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11643 Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11644 Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-11645 Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11646 Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11649 Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11650 Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11651 Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11652 Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11653 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11656 Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11658 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11659 Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11660 Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11662 Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11663 Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11664 Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11666 Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11667 Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the GPU process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11668 Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11670 Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11671 Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11673 Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11674 Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11675 Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11676 Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11678 Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11681 Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11682 Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11683 Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11684 Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11688 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11689 Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11691 Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11692 Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11693 Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11694 Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11695 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11697 Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-11700 Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-11701 Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

cdwdataviz
runtimedataviz

CVE-2026-12007 Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12008 Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdwdataviz
runtimedataviz

CVE-2026-12011 Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12012 Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12014 Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12015 Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12016 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12017 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12018 Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

cdsw-web

CVE-2026-12019 Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12024 Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12025 Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12027 Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12029 Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12031 Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12033 Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12034 Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

cdwdataviz
runtimedataviz

CVE-2026-12035 Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12064 When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline
python-runtime

CVE-2026-12437 Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12438 Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12439 Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12440 Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12441 Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12442 Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12443 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

cdsw-web

CVE-2026-12444 Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: High)

cdsw-web

CVE-2026-12445 Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

cdsw-web

CVE-2026-12446 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12447 Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12448 Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12449 Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

cdsw-web

CVE-2026-12450 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12451 Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12452 Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12453 Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12454 Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12455 Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12456 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)

cdsw-web

CVE-2026-12457 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12458 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12459 Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12460 Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: High)

cdsw-web

CVE-2026-12461 Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12462 Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12463 Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12464 Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12465 Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12466 Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12467 Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12468 Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-12469 Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

cdsw-web

CVE-2026-21998 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22001 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22002 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22004 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22005 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22009 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22015 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22017 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-22772 Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.

cdsw-s2i-builder-buildah

CVE-2026-23344 In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix use-after-free on error path In the error path of sev_tsm_init_locked(), the code dereferences 't' after it has been freed with kfree(). The pr_err() statement attempts to access t->tio_en and t->tio_init_done after the memory has been released. Move the pr_err() call before kfree(t) to access the fields while the memory is still valid. This issue reported by Smatch static analyser

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-23390 In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow The dma_map_sg tracepoint can trigger a perf buffer overflow when tracing large scatter-gather lists. With devices like virtio-gpu creating large DRM buffers, nents can exceed 1000 entries, resulting in: phys_addrs: 1000 * 8 bytes = 8,000 bytes dma_addrs: 1000 * 8 bytes = 8,000 bytes lengths: 1000 * 4 bytes = 4,000 bytes Total: ~20,000 bytes This exceeds PERF_MAX_TRACE_SIZE (8192 bytes), causing: WARNING: CPU: 0 PID: 5497 at kernel/trace/trace_event_perf.c:405 perf buffer not large enough, wanted 24620, have 8192 Cap all three dynamic arrays at 128 entries using min() in the array size calculation. This ensures arrays are only as large as needed (up to the cap), avoiding unnecessary memory allocation for small operations while preventing overflow for large ones. The tracepoint now records the full nents/ents counts and a truncated flag so users can see when data has been capped. Changes in v2: - Use min(nents, DMA_TRACE_MAX_ENTRIES) for dynamic array sizing instead of fixed DMA_TRACE_MAX_ENTRIES allocation (feedback from Steven Rostedt) - This allocates only what's needed up to the cap, avoiding waste for small operations Reviwed-by: Sean Anderson <sean.anderson@linux.dev>

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-23427 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_durable_handle_context() unconditionally assigns dh_info->fp->conn to the current connection when handling a DURABLE_REQ_V2 context with SMB2_FLAGS_REPLAY_OPERATION. ksmbd_lookup_fd_cguid() does not filter by fp->conn, so it returns file handles that are already actively connected. The unconditional overwrite replaces fp->conn, and when the overwriting connection is subsequently freed, __ksmbd_close_fd() dereferences the stale fp->conn via spin_lock(&fp->conn->llist_lock), causing a use-after-free. KASAN report: [ 7.349357] ================================================================== [ 7.349607] BUG: KASAN: slab-use-after-free in _raw_spin_lock+0x75/0xe0 [ 7.349811] Write of size 4 at addr ffff8881056ac18c by task kworker/1:2/108 [ 7.350010] [ 7.350064] CPU: 1 UID: 0 PID: 108 Comm: kworker/1:2 Not tainted 7.0.0-rc3+ #58 PREEMPTLAZY [ 7.350068] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 7.350070] Workqueue: ksmbd-io handle_ksmbd_work [ 7.350083] Call Trace: [ 7.350087] <TASK> [ 7.350087] dump_stack_lvl+0x64/0x80 [ 7.350094] print_report+0xce/0x660 [ 7.350100] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 7.350101] ? __pfx___mod_timer+0x10/0x10 [ 7.350106] ? _raw_spin_lock+0x75/0xe0 [ 7.350108] kasan_report+0xce/0x100 [ 7.350109] ? _raw_spin_lock+0x75/0xe0 [ 7.350114] kasan_check_range+0x105/0x1b0 [ 7.350116] _raw_spin_lock+0x75/0xe0 [ 7.350118] ? __pfx__raw_spin_lock+0x10/0x10 [ 7.350119] ? __call_rcu_common.constprop.0+0x25e/0x780 [ 7.350125] ? close_id_del_oplock+0x2cc/0x4e0 [ 7.350128] __ksmbd_close_fd+0x27f/0xaf0 [ 7.350131] ksmbd_close_fd+0x135/0x1b0 [ 7.350133] smb2_close+0xb19/0x15b0 [ 7.350142] ? __pfx_smb2_close+0x10/0x10 [ 7.350143] ? xas_load+0x18/0x270 [ 7.350146] ? _raw_spin_lock+0x84/0xe0 [ 7.350148] ? __pfx__raw_spin_lock+0x10/0x10 [ 7.350150] ? _raw_spin_unlock+0xe/0x30 [ 7.350151] ? ksmbd_smb2_check_message+0xeb2/0x24c0 [ 7.350153] ? ksmbd_tree_conn_lookup+0xcd/0xf0 [ 7.350154] handle_ksmbd_work+0x40f/0x1080 [ 7.350156] process_one_work+0x5fa/0xef0 [ 7.350162] ? assign_work+0x122/0x3e0 [ 7.350163] worker_thread+0x54b/0xf70 [ 7.350165] ? __pfx_worker_thread+0x10/0x10 [ 7.350166] kthread+0x346/0x470 [ 7.350170] ? recalc_sigpending+0x19b/0x230 [ 7.350176] ? __pfx_kthread+0x10/0x10 [ 7.350178] ret_from_fork+0x4fb/0x6c0 [ 7.350183] ? __pfx_ret_from_fork+0x10/0x10 [ 7.350185] ? __switch_to+0x36c/0xbe0 [ 7.350188] ? __pfx_kthread+0x10/0x10 [ 7.350190] ret_from_fork_asm+0x1a/0x30 [ 7.350197] </TASK> [ 7.350197] [ 7.355160] Allocated by task 123: [ 7.355261] kasan_save_stack+0x33/0x60 [ 7.355373] kasan_save_track+0x14/0x30 [ 7.355484] __kasan_kmalloc+0x8f/0xa0 [ 7.355593] ksmbd_conn_alloc+0x44/0x6d0 [ 7.355711] ksmbd_kthread_fn+0x243/0xd70 [ 7.355839] kthread+0x346/0x470 [ 7.355942] ret_from_fork+0x4fb/0x6c0 [ 7.356051] ret_from_fork_asm+0x1a/0x30 [ 7.356164] [ 7.356214] Freed by task 134: [ 7.356305] kasan_save_stack+0x33/0x60 [ 7.356416] kasan_save_track+0x14/0x30 [ 7.356527] kasan_save_free_info+0x3b/0x60 [ 7.356646] __kasan_slab_free+0x43/0x70 [ 7.356761] kfree+0x1ca/0x430 [ 7.356862] ksmbd_tcp_disconnect+0x59/0xe0 [ 7.356993] ksmbd_conn_handler_loop+0x77e/0xd40 [ 7.357138] kthread+0x346/0x470 [ 7.357240] ret_from_fork+0x4fb/0x6c0 [ 7.357350] ret_from_fork_asm+0x1a/0x30 [ 7.357463] [ 7.357513] The buggy address belongs to the object at ffff8881056ac000 [ 7.357513] which belongs to the cache kmalloc-1k of size 1024 [ 7.357857] The buggy address is located 396 bytes inside of [ 7.357857] freed 1024-byte region ---truncated---

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-23469 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before suspending the GPU The runtime PM suspend callback doesn't know whether the IRQ handler is in progress on a different CPU core and doesn't wait for it to finish. Depending on timing, the IRQ handler could be running while the GPU is suspended, leading to kernel crashes when trying to access GPU registers. See example signature below. In a power off sequence initiated by the runtime PM suspend callback, wait for any IRQ handlers in progress on other CPU cores to finish, by calling synchronize_irq(). At the same time, remove the runtime PM resume/put calls in the threaded IRQ handler. On top of not being the right approach to begin with, and being at the wrong place as they should have wrapped all GPU register accesses, the driver would hit a deadlock between synchronize_irq() being called from a runtime PM suspend callback, holding the device power lock, and the resume callback requiring the same. Example crash signature on a TI AM68 SK platform: [ 337.241218] SError Interrupt on CPU0, code 0x00000000bf000000 -- SError [ 337.241239] CPU: 0 UID: 0 PID: 112 Comm: irq/234-gpu Tainted: G M 6.17.7-B2C-00005-g9c7bbe4ea16c #2 PREEMPT [ 337.241246] Tainted: [M]=MACHINE_CHECK [ 337.241249] Hardware name: Texas Instruments AM68 SK (DT) [ 337.241252] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 337.241256] pc : pvr_riscv_irq_pending+0xc/0x24 [ 337.241277] lr : pvr_device_irq_thread_handler+0x64/0x310 [ 337.241282] sp : ffff800085b0bd30 [ 337.241284] x29: ffff800085b0bd50 x28: ffff0008070d9eab x27: ffff800083a5ce10 [ 337.241291] x26: ffff000806e48f80 x25: ffff0008070d9eac x24: 0000000000000000 [ 337.241296] x23: ffff0008068e9bf0 x22: ffff0008068e9bd0 x21: ffff800085b0bd30 [ 337.241301] x20: ffff0008070d9e00 x19: ffff0008068e9000 x18: 0000000000000001 [ 337.241305] x17: 637365645f656c70 x16: 0000000000000000 x15: ffff000b7df9ff40 [ 337.241310] x14: 0000a585fe3c0d0e x13: 000000999704f060 x12: 000000000002771a [ 337.241314] x11: 00000000000000c0 x10: 0000000000000af0 x9 : ffff800085b0bd00 [ 337.241318] x8 : ffff0008071175d0 x7 : 000000000000b955 x6 : 0000000000000003 [ 337.241323] x5 : 0000000000000000 x4 : 0000000000000002 x3 : 0000000000000000 [ 337.241327] x2 : ffff800080e39d20 x1 : ffff800080e3fc48 x0 : 0000000000000000 [ 337.241333] Kernel panic - not syncing: Asynchronous SError Interrupt [ 337.241337] CPU: 0 UID: 0 PID: 112 Comm: irq/234-gpu Tainted: G M 6.17.7-B2C-00005-g9c7bbe4ea16c #2 PREEMPT [ 337.241342] Tainted: [M]=MACHINE_CHECK [ 337.241343] Hardware name: Texas Instruments AM68 SK (DT) [ 337.241345] Call trace: [ 337.241348] show_stack+0x18/0x24 (C) [ 337.241357] dump_stack_lvl+0x60/0x80 [ 337.241364] dump_stack+0x18/0x24 [ 337.241368] vpanic+0x124/0x2ec [ 337.241373] abort+0x0/0x4 [ 337.241377] add_taint+0x0/0xbc [ 337.241384] arm64_serror_panic+0x70/0x80 [ 337.241389] do_serror+0x3c/0x74 [ 337.241392] el1h_64_error_handler+0x30/0x48 [ 337.241400] el1h_64_error+0x6c/0x70 [ 337.241404] pvr_riscv_irq_pending+0xc/0x24 (P) [ 337.241410] irq_thread_fn+0x2c/0xb0 [ 337.241416] irq_thread+0x170/0x334 [ 337.241421] kthread+0x12c/0x210 [ 337.241428] ret_from_fork+0x10/0x20 [ 337.241434] SMP: stopping secondary CPUs [ 337.241451] Kernel Offset: disabled [ 337.241453] CPU features: 0x040000,02002800,20002001,0400421b [ 337.241456] Memory Limit: none [ 337.457921] ---[ end Kernel panic - not syncing: Asynchronous SError Interrupt ]---

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-24137 sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target name sourced from signed target metadata; however, it does not validate that the resulting path stays within the cache base directory. A malicious TUF repository can trigger arbitrary file overwriting, limited to the permissions that the calling process has. Note that this should only affect clients that are directly using the TUF client in sigstore/sigstore or are using an older version of Cosign. Public Sigstore deployment users are unaffected, as TUF metadata is validated by a quorum of trusted collaborators. This issue has been fixed in version 1.10.4. As a workaround, users can disable disk caching for the legacy client by setting SIGSTORE_NO_CACHE=true in the environment, migrate to https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf, or upgrade to the latest sigstore/sigstore release.

cdsw-s2i-builder-buildah

CVE-2026-29169 A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

dex-livy-runtime-2.4.8-7.1.9.1078
dex-livy-runtime-3.3.2-7.1.9.1078-compat
dex-livy-server-2.4.8-7.1.9.1078
dex-spark-history-server-2.4.8-7.1.9.1078
dex-spark-runtime-2.4.8-7.1.9.1078
dex-spark-runtime-3.3.2-7.1.9.1078-compat

CVE-2026-30836 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

cdwdataviz
runtimedataviz

CVE-2026-31635 In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing check is inverted, so oversized RESPONSE authenticators are accepted and passed to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an impossible length and hit BUG_ON(len). Decoded from the original latest-net reproduction logs with scripts/decode_stacktrace.sh: RIP: __skb_to_sgvec() [net/core/skbuff.c:5285 (discriminator 1)] Call Trace: skb_to_sgvec() [net/core/skbuff.c:5305] rxgk_decrypt_skb() [net/rxrpc/rxgk_common.h:81] rxgk_verify_response() [net/rxrpc/rxgk.c:1268] rxrpc_process_connection() [net/rxrpc/conn_event.c:266 net/rxrpc/conn_event.c:364 net/rxrpc/conn_event.c:386] process_one_work() [kernel/workqueue.c:3281] worker_thread() [kernel/workqueue.c:3353 kernel/workqueue.c:3440] kthread() [kernel/kthread.c:436] ret_from_fork() [arch/x86/kernel/process.c:164] Reject authenticator lengths that exceed the remaining packet payload.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-31688 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

cmlserving-triton-runtime
dex-runtime-python-builder-7.1.9.1078-compat
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-31718 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a durable file handle survives session disconnect (TCP close without SMB2_LOGOFF), session_fd_check() sets fp->conn = NULL to preserve the handle for later reconnection. However, it did not clean up the byte-range locks on fp->lock_list. Later, when the durable scavenger thread times out and calls __ksmbd_close_fd(NULL, fp), the lock cleanup loop did: spin_lock(&fp->conn->llist_lock); This caused a slab use-after-free because fp->conn was NULL and the original connection object had already been freed by ksmbd_tcp_disconnect(). The root cause is asymmetric cleanup: lock entries (smb_lock->clist) were left dangling on the freed conn->lock_list while fp->conn was nulled out. To fix this issue properly, we need to handle the lifetime of smb_lock->clist across three paths: - Safely skip clist deletion when list is empty and fp->conn is NULL. - Remove the lock from the old connection's lock_list in session_fd_check() - Re-add the lock to the new connection's lock_list in ksmbd_reopen_durable_fd().

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-31769 In the Linux kernel, the following vulnerability has been resolved: gpib: fix use-after-free in IO ioctl handlers The IBRD, IBWRT, IBCMD, and IBWAIT ioctl handlers use a gpib_descriptor pointer after board->big_gpib_mutex has been released. A concurrent IBCLOSEDEV ioctl can free the descriptor via close_dev_ioctl() during this window, causing a use-after-free. The IO handlers (read_ioctl, write_ioctl, command_ioctl) explicitly release big_gpib_mutex before calling their handler. wait_ioctl() is called with big_gpib_mutex held, but ibwait() releases it internally when wait_mask is non-zero. In all four cases, the descriptor pointer obtained from handle_to_descriptor() becomes unprotected. Fix this by introducing a kernel-only descriptor_busy reference count in struct gpib_descriptor. Each handler atomically increments descriptor_busy under file_priv->descriptors_mutex before releasing the lock, and decrements it when done. close_dev_ioctl() checks descriptor_busy under the same lock and rejects the close with -EBUSY if the count is non-zero. A reference count rather than a simple flag is necessary because multiple handlers can operate on the same descriptor concurrently (e.g. IBRD and IBWAIT on the same handle from different threads). A separate counter is needed because io_in_progress can be cleared from unprivileged userspace via the IBWAIT ioctl (through general_ibstatus() with set_mask containing CMPL), which would allow an attacker to bypass a check based solely on io_in_progress. The new descriptor_busy counter is only modified by the kernel IO paths. The lock ordering is consistent (big_gpib_mutex -> descriptors_mutex) and the handlers only hold descriptors_mutex briefly during the lookup, so there is no deadlock risk and no impact on IO throughput.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-31786 In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and copy till it finds a NUL. 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| 00000010 b9 a8 01 42 6f 2e 32 |...Bo.2| 00000017 So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| 00000010 b9 a8 01 42 |...B| 00000014 (the above have a hack to embed a zero inside and check it's returned correctly). This is XSA-485 / CVE-2026-31786

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2026-31787 In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vma(). Since may_split is NULL, the split is allowed. vm_area_dup() copies vm_private_data (a pages array allocated in alloc_empty_pages()) into the new VMA without any fixup, because there is no .open callback. Both VMAs now point to the same pages array. When the unmapped portion is closed, privcmd_close() calls: - xen_unmap_domain_gfn_range() - xen_free_unpopulated_pages() - kvfree(pages) The surviving VMA still holds the dangling pointer. When it is later destroyed, the same sequence runs again, which leads to a double free. Fix this issue by adding a .may_split callback denying the VMA split. This is XSA-487 / CVE-2026-31787

dex-runtime-python-builder-7.1.9.1078-compat

CVE-2026-32285 The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

cdwdataviz
runtimedataviz

CVE-2026-32286 The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

cdsw-api
cdsw-user-management

CVE-2026-32738 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-32739 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-32741 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-32792 NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-32814 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-32882 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-33033 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

cdwdataviz
runtimedataviz

CVE-2026-33034 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

cdwdataviz
runtimedataviz

CVE-2026-33164 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-33165 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-33278 NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-33815 Memory-safety vulnerability in github.com/jackc/pgx/v5.

cdwdataviz
runtimedataviz

CVE-2026-33816 Memory-safety vulnerability in github.com/jackc/pgx/v5.

cdwdataviz
runtimedataviz

CVE-2026-34267 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34270 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34271 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34276 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34278 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34293 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34303 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34304 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34308 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34317 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34318 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34319 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-34601 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

cdsw-web

CVE-2026-35236 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-35237 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-35238 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-35239 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-35240 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-40097 Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. When processing a device-attest-01 ACME challenge using TPM attestation, Step CA validates that the AK certificate contains the tcg-kp-AIKCertificate Extended Key Usage OID. During this validation, the EKU extension value is decoded from its ASN.1 representation and the first element is checked. A crafted certificate could include an EKU extension that decodes to an empty sequence, causing the code to panic when accessing the first element of the empty slice. This vulnerability is only reachable when a device-attest-01 ACME challenge with TPM attestation is configured. Deployments not using TPM device attestation are not affected. This vulnerability is fixed in 0.30.0-rc3.

cdwdataviz
runtimedataviz

CVE-2026-40622 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-41069 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-41071 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-41292 NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-41324 basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.list()`, causing the client process to consume memory until it becomes unstable or crashes. Version 5.3.0 fixes the issue.

cdsw-web

CVE-2026-42328 No description available.

cdp-private
parcel

CVE-2026-42534 NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-42798 Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-42923 NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will keep performing the allowed hash calculations on the NSEC3 records and will not limit the work by the mitigation introduced in 1.19.1. As a side effect, a global lock for the negative cache will be held for the duration of the hashing, blocking other threads that need to consult the negative cache. Coordinated attacks could raise the vulnerability to denial of service. Unbound 1.25.1 contains a patch with a fix to bound the vulnerable code path with the existing limit for NSEC3 hash calculations.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-42944 NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-42959 NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-42960 NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-43083 In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.

cmlserving-triton-runtime
kserve_huggingfaceserver
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-43125 In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree(). Add length validation to prevent potential buffer overflow.

cmlserving-triton-runtime
dex-runtime-python-builder-7.1.9.1078-compat
kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3

CVE-2026-43197 In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure") the message would be placed in printk_shared_pbufs, a static global buffer, so KASAN had harder time catching OOB accesses. Now we see: printk: console [netcon_ext0] enabled BUG: KASAN: slab-out-of-bounds in string+0x1f7/0x240 Read of size 1 at addr ffff88813b6d4c00 by task pr/netcon_ext0/594 CPU: 65 UID: 0 PID: 594 Comm: pr/netcon_ext0 Not tainted 6.19.0-11754-g4246fd6547c9 Call Trace: kasan_report+0xe4/0x120 string+0x1f7/0x240 vsnprintf+0x655/0xba0 scnprintf+0xba/0x120 netconsole_write+0x3fe/0xa10 nbcon_emit_next_record+0x46e/0x860 nbcon_kthread_func+0x623/0x750 Allocated by task 1: nbcon_alloc+0x1ea/0x450 register_console+0x26b/0xe10 init_netconsole+0xbb0/0xda0 The buggy address belongs to the object at ffff88813b6d4000 which belongs to the cache kmalloc-4k of size 4096 The buggy address is located 0 bytes to the right of allocated 3072-byte region [ffff88813b6d4000, ffff88813b6d4c00)

cmlserving-triton-runtime
kserve_huggingfaceserver
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-43198 In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.

cmlserving-triton-runtime
dex-runtime-python-builder-7.1.9.1078-compat
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-43274 In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() The cluster_cfg array is dynamically allocated to hold per-CPU configuration structures, with its size based on the number of online CPUs. Previously, this array was indexed using hartid, which may be non-contiguous or exceed the bounds of the array, leading to out-of-bounds access. Switch to using cpuid as the index, as it is guaranteed to be within the valid range provided by for_each_online_cpu().

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-43376 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in places like opinfo_get() and proc_show_files(). Since there is no RCU grace period delay between nullifying the pointer and freeing the memory, a reader can still access oplock_info structure after it has been freed. This can leads to a use-after-free especially in opinfo_get() where atomic_inc_not_zero() is called on already freed memory. Fix this by switching to deferred freeing using call_rcu().

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-43402 In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function pointers during KUnit testing. The crash was traced back to the pidfs rhashtable conversion which replaced the 24-byte rb_node with an 8-byte rhash_head in struct pid, shrinking it from 160 to 144 bytes. struct kthread (without CONFIG_BLK_CGROUP) is also 144 bytes. With CONFIG_SLAB_MERGE_DEFAULT and SLAB_HWCACHE_ALIGN both round up to 192 bytes and share the same slab cache. struct pid.rcu.func and struct kthread.affinity_node both sit at offset 0x78. When a kthread exits via make_task_dead() it bypasses kthread_exit() and misses the affinity_node cleanup. free_kthread_struct() frees the memory while the node is still linked into the global kthread_affinity_list. A subsequent list_del() by another kthread writes through dangling list pointers into the freed and reused memory, corrupting the pid's rcu.func pointer. Instead of patching free_kthread_struct() to handle the missed cleanup, consolidate all kthread exit paths. Turn kthread_exit() into a macro that calls do_exit() and add kthread_do_exit() which is called from do_exit() for any task with PF_KTHREAD set. This guarantees that kthread-specific cleanup always happens regardless of the exit path - make_task_dead(), direct do_exit(), or kthread_exit(). Replace __to_kthread() with a new tsk_is_kthread() accessor in the public header. Export do_exit() since module code using the kthread_exit() macro now needs it directly.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-43465 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_tail(). The referenced commit in the fixes tag corrected the assumption in the mlx5 driver that the XDP buffer layout doesn't change during a program execution. However, this fix introduced another issue: the dropped fragments still need to be counted on the driver side to avoid page fragment reference counting issues. The issue was discovered by the drivers/net/xdp.py selftest, more specifically the test_xdp_native_tx_mb: - The mlx5 driver allocates a page_pool page and initializes it with a frag counter of 64 (pp_ref_count=64) and the internal frag counter to 0. - The test sends one packet with no payload. - On RX (mlx5e_skb_from_cqe_mpwrq_nonlinear()), mlx5 configures the XDP buffer with the packet data starting in the first fragment which is the page mentioned above. - The XDP program runs and calls bpf_xdp_pull_data() which moves the header into the linear part of the XDP buffer. As the packet doesn't contain more data, the program drops the tail fragment since it no longer contains any payload (pp_ref_count=63). - mlx5 device skips counting this fragment. Internal frag counter remains 0. - mlx5 releases all 64 fragments of the page but page pp_ref_count is 63 => negative reference counting error. Resulting splat during the test: WARNING: CPU: 0 PID: 188225 at ./include/net/page_pool/helpers.h:297 mlx5e_page_release_fragmented.isra.0+0xbd/0xe0 [mlx5_core] Modules linked in: [...] CPU: 0 UID: 0 PID: 188225 Comm: ip Not tainted 6.18.0-rc7_for_upstream_min_debug_2025_12_08_11_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:mlx5e_page_release_fragmented.isra.0+0xbd/0xe0 [mlx5_core] [...] Call Trace: <TASK> mlx5e_free_rx_mpwqe+0x20a/0x250 [mlx5_core] mlx5e_dealloc_rx_mpwqe+0x37/0xb0 [mlx5_core] mlx5e_free_rx_descs+0x11a/0x170 [mlx5_core] mlx5e_close_rq+0x78/0xa0 [mlx5_core] mlx5e_close_queues+0x46/0x2a0 [mlx5_core] mlx5e_close_channel+0x24/0x90 [mlx5_core] mlx5e_close_channels+0x5d/0xf0 [mlx5_core] mlx5e_safe_switch_params+0x2ec/0x380 [mlx5_core] mlx5e_change_mtu+0x11d/0x490 [mlx5_core] mlx5e_change_nic_mtu+0x19/0x30 [mlx5_core] netif_set_mtu_ext+0xfc/0x240 do_setlink.isra.0+0x226/0x1100 rtnl_newlink+0x7a9/0xba0 rtnetlink_rcv_msg+0x220/0x3c0 netlink_rcv_skb+0x4b/0xf0 netlink_unicast+0x255/0x380 netlink_sendmsg+0x1f3/0x420 __sock_sendmsg+0x38/0x60 ____sys_sendmsg+0x1e8/0x240 ___sys_sendmsg+0x7c/0xb0 [...] __sys_sendmsg+0x5f/0xb0 do_syscall_64+0x55/0xc70 The problem applies for XDP_PASS as well which is handled in a different code path in the driver. This patch fixes the issue by doing page frag counting on all the original XDP buffer fragments for all relevant XDP actions (XDP_TX , XDP_REDIRECT and XDP_PASS). This is basically reverting to the original counting before the commit in the fixes tag. As frag_page is still pointing to the original tail, the nr_frags parameter to xdp_update_skb_frags_info() needs to be calculated in a different way to reflect the new nr_frags.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-44240 basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext._partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.

cdsw-web

CVE-2026-44288 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44289 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44290 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44291 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44292 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44293 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44294 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, decode, verify, or conversion functions to fail during compilation. This vulnerability is fixed in 7.5.6 and 8.0.2.

cdsw-web

CVE-2026-44390 NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the compression tree lookup failure and eventually not increment the compression counter for those operations. Unbound 1.25.1 contains a patch with a fix that increments the compression counter regardless of the compression tree lookup. This is a complement fix to CVE-2024-8508.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-44608 NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-44902 opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0.

cdsw-web

CVE-2026-45135 Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.

cdwdataviz
runtimedataviz

CVE-2026-45382 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-45383 libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-45692 Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.

cdwdataviz
runtimedataviz

CVE-2026-45898 In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call queue_work() with the expectation that queue_work() would have no effect if work was already pending. The problem is that a free list of struct iwcm_work is used (for which struct work_struct is embedded), so each call to queue_work() is basically unique and therefore does indeed queue the work. This causes a problem in the work handler which walks the work_list until it's empty to process entries. This means that a single run of the work handler could process item N+1 and release it back to the free list while the actual workqueue entry is still queued. It could then get reused (INIT_WORK...) and lead to list corruption in the workqueue logic. Fix this by just removing the work_list. The workqueue already does this for us. This fixes the following error that was observed when stress testing with ucmatose on an Intel E830 in iWARP mode: [ 151.465780] list_del corruption. next->prev should be ffff9f0915c69c08, but was ffff9f0a1116be08. (next=ffff9f0a15b11c08) [ 151.466639] ------------[ cut here ]------------ [ 151.466986] kernel BUG at lib/list_debug.c:67! [ 151.467349] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 151.467753] CPU: 14 UID: 0 PID: 2306 Comm: kworker/u64:18 Not tainted 6.19.0-rc4+ #1 PREEMPT(voluntary) [ 151.468466] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 151.469192] Workqueue: 0x0 (iw_cm_wq) [ 151.469478] RIP: 0010:__list_del_entry_valid_or_report+0xf0/0x100 [ 151.469942] Code: c7 58 5f 4c b2 e8 10 50 aa ff 0f 0b 48 89 ef e8 36 57 cb ff 48 8b 55 08 48 89 e9 48 89 de 48 c7 c7 a8 5f 4c b2 e8 f0 4f aa ff <0f> 0b 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 [ 151.471323] RSP: 0000:ffffb15644e7bd68 EFLAGS: 00010046 [ 151.471712] RAX: 000000000000006d RBX: ffff9f0915c69c08 RCX: 0000000000000027 [ 151.472243] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff9f0a37d9c600 [ 151.472768] RBP: ffff9f0a15b11c08 R08: 0000000000000000 R09: c0000000ffff7fff [ 151.473294] R10: 0000000000000001 R11: ffffb15644e7bba8 R12: ffff9f092339ee68 [ 151.473817] R13: ffff9f0900059c28 R14: ffff9f092339ee78 R15: 0000000000000000 [ 151.474344] FS: 0000000000000000(0000) GS:ffff9f0a847b5000(0000) knlGS:0000000000000000 [ 151.474934] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 151.475362] CR2: 0000559e233a9088 CR3: 000000020296b004 CR4: 0000000000770ef0 [ 151.475895] PKRU: 55555554 [ 151.476118] Call Trace: [ 151.476331] <TASK> [ 151.476497] move_linked_works+0x49/0xa0 [ 151.476792] __pwq_activate_work.isra.46+0x2f/0xa0 [ 151.477151] pwq_dec_nr_in_flight+0x1e0/0x2f0 [ 151.477479] process_scheduled_works+0x1c8/0x410 [ 151.477823] worker_thread+0x125/0x260 [ 151.478108] ? __pfx_worker_thread+0x10/0x10 [ 151.478430] kthread+0xfe/0x240 [ 151.478671] ? __pfx_kthread+0x10/0x10 [ 151.478955] ? __pfx_kthread+0x10/0x10 [ 151.479240] ret_from_fork+0x208/0x270 [ 151.479523] ? __pfx_kthread+0x10/0x10 [ 151.479806] ret_from_fork_asm+0x1a/0x30 [ 151.480103] </TASK>

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-45966 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL pointer dereference in __unix_needs_revalidation When receiving file descriptors via SCM_RIGHTS, both the socket pointer and the socket's sk pointer can be NULL during socket setup or teardown, causing NULL pointer dereferences in __unix_needs_revalidation(). This is a regression in AppArmor 5.0.0 (kernel 6.17+) where the new __unix_needs_revalidation() function was added without proper NULL checks. The crash manifests as: BUG: kernel NULL pointer dereference, address: 0x0000000000000018 RIP: aa_file_perm+0xb7/0x3b0 (or +0xbe/0x3b0, +0xc0/0x3e0) Call Trace: apparmor_file_receive+0x42/0x80 security_file_receive+0x2e/0x50 receive_fd+0x1d/0xf0 scm_detach_fds+0xad/0x1c0 The function dereferences sock->sk->sk_family without checking if either sock or sock->sk is NULL first. Add NULL checks for both sock and sock->sk before accessing sk_family.

ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-45993 In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add spectre boundry for syscall dispatch table The LoongArch syscall number is directly controlled by userspace, but does not have a array_index_nospec() boundry to prevent access past the syscall function pointer tables.

cmlserving-triton-runtime
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3

CVE-2026-46039 In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket. Rather than rounding up the value to be tested (which might overflow), round down the size of the available data.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-46118 In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle() commit 6d3789d347a7 ("papr-hvpipe: convert papr_hvpipe_dev_create_handle() to FD_PREPARE()"), changed the create handle to FD_PREPARE(), but it caused kernel null-ptr-deref because after call to retain_and_null_ptr(src_info), src_info is re-used for adding it to the global list. Getting the following kernel panic in papr_hvpipe_dev_create_handle() when trying to add src_info to the list. Kernel attempted to write user page (0) - exploit attempt? (uid: 0) BUG: Kernel NULL pointer dereference on write at 0x00000000 Faulting instruction address: 0xc0000000001b44a0 Oops: Kernel access of bad area, sig: 11 [#1] ... Call Trace: papr_hvpipe_dev_ioctl+0x1f4/0x48c (unreliable) sys_ioctl+0x528/0x1064 system_call_exception+0x128/0x360 system_call_vectored_common+0x15c/0x2ec Now, the error handling with FD_PREPARE's file cleanup and __free(kfree) auto cleanup is getting too convoluted. This is mainly because we need to ensure only 1 user get the srcID handle. To simplify this, we allocate prepare the src_info in the beginning and add it to the global list under a spinlock after checking that no duplicates exist. This simplify the error handling where if the FD_ADD fails, we can simply remove the src_info from the list and consume any pending msg in hvpipe to be cleared, after src_info became visible in the global list.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-meta-llama3.3-70b-instruct-v2.0.3
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-cosmos-reason2-8b-v1.7.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v2.0.3
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-nano-v2.0.3
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-3-super-120b-a12b-v2.0.3
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-120b-v2.0.3
nim-openai-gpt-oss-20b-v1.12.4
nim-openai-gpt-oss-20b-v2.0.3
python-runtime

CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). For the epoll-watches-epoll case, f_op->release is ep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which kfree()s the watched struct eventpoll. Its embedded ->refs hlist_head is exactly where epi->fllink.pprev points, so the subsequent hlist_del_rcu()'s "*pprev = next" scribbles into freed kmalloc-192 memory. In addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot backing @file could be recycled by alloc_empty_file() -- reinitializing f_lock and f_ep -- while ep_remove() is still nominally inside that lock. The upshot is an attacker-controllable kmem_cache_free() against the wrong slab cache. Pin @file via epi_fget() at the top of ep_remove() and gate the critical section on the pin succeeding. With the pin held @file cannot reach refcount zero, which holds __fput() off and transitively keeps the watched struct eventpoll alive across the hlist_del_rcu() and the f_lock use, closing both UAFs. If the pin fails @file has already reached refcount zero and its __fput() is in flight. Because we bailed before clearing f_ep, that path takes the eventpoll_release() slow path into eventpoll_release_file() and blocks on ep->mtx until the waiter side's ep_clear_and_put() drops it. The bailed epi's share of ep->refcount stays intact, so the trailing ep_refcount_dec_and_test() in ep_clear_and_put() cannot free the eventpoll out from under eventpoll_release_file(); the orphaned epi is then cleaned up there. A successful pin also proves we are not racing eventpoll_release_file() on this epi, so drop the now-redundant re-check of epi->dying under f_lock. The cheap lockless READ_ONCE(epi->dying) fast-path bailout stays.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-46315 In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.

cmlserving-triton-runtime
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-46316 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command handlers hold its_lock, the GITS_CTLR write path holds cmd_lock, and the path that clears EnableLPIs in a redistributor's GICR_CTLR holds neither. Two or more of them can drain the same cache concurrently, and if each one observes the same entry, erases it and then puts it, the single reference the cache holds on that entry is dropped more than once. The entry can then be freed while an ITE still maps it. xa_erase() is atomic and returns the previous entry, so put only the entry that this context actually removed. The cache reference is then dropped exactly once per entry even when the invalidations run concurrently, and the behavior is unchanged when only one context runs.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-46325 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. The core issue is that rxe_set_page() is called with mr->page_size step increments, but the page_list stores individual struct page pointers, each representing PAGE_SIZE of memory. ib_sg_to_page() has ensured that when i>=1 either a) SG[i-1].dma_end and SG[i].dma_addr are contiguous or b) SG[i-1].dma_end and SG[i].dma_addr are mr->page_size aligned. This leads to incorrect iova-to-va conversion in scenarios: 1) page_size < PAGE_SIZE (e.g., MR: 4K, system: 64K): ibmr->iova = 0x181800 sg[0]: dma_addr=0x181800, len=0x800 sg[1]: dma_addr=0x173000, len=0x1000 Access iova = 0x181800 + 0x810 = 0x182010 Expected VA: 0x173010 (second SG, offset 0x10) Before fix: - index = (0x182010 >> 12) - (0x181800 >> 12) = 1 - page_offset = 0x182010 & 0xFFF = 0x10 - xarray[1] stores system page base 0x170000 - Resulting VA: 0x170000 + 0x10 = 0x170010 (wrong) 2) page_size > PAGE_SIZE (e.g., MR: 64K, system: 4K): ibmr->iova = 0x18f800 sg[0]: dma_addr=0x18f800, len=0x800 sg[1]: dma_addr=0x170000, len=0x1000 Access iova = 0x18f800 + 0x810 = 0x190010 Expected VA: 0x170010 (second SG, offset 0x10) Before fix: - index = (0x190010 >> 16) - (0x18f800 >> 16) = 1 - page_offset = 0x190010 & 0xFFFF = 0x10 - xarray[1] stores system page for dma_addr 0x170000 - Resulting VA: system page of 0x170000 + 0x10 = 0x170010 (wrong) Yi Zhang reported a kernel panic[1] years ago related to this defect. Solution: 1. Replace xarray with pre-allocated rxe_mr_page array for sequential indexing (all MR page indices are contiguous) 2. Each rxe_mr_page stores both struct page* and offset within the system page 3. Handle MR page_size != PAGE_SIZE relationships: - page_size > PAGE_SIZE: Split MR pages into multiple system pages - page_size <= PAGE_SIZE: Store offset within system page 4. Add boundary checks and compatibility validation This ensures correct iova-to-va conversion regardless of MR page size and system PAGE_SIZE relationship, while improving performance through array-based sequential access. Tests on 4K and 64K PAGE_SIZE hosts: - rdma-core/pytests $ ./build/bin/run_tests.py --dev eth0_rxe - blktest: $ TIMEOUT=30 QUICK_RUN=1 USE_RXE=1 NVMET_TRTYPES=rdma ./check nvme srp rnbd [1] https://lore.kernel.org/all/CAHj4cs9XRqE25jyVw9rj9YugffLn5+f=1znaBEnu1usLOciD+g@mail.gmail.com/T/

cmlserving-triton-runtime
kserve_huggingfaceserver
ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-python3.10-cuda
ml-runtime-pbj-workbench-python3.10-standard
ml-runtime-pbj-workbench-python3.11-cuda
ml-runtime-pbj-workbench-python3.11-standard
ml-runtime-pbj-workbench-python3.12-cuda
ml-runtime-pbj-workbench-python3.12-standard
ml-runtime-pbj-workbench-python3.13-cuda
ml-runtime-pbj-workbench-python3.13-standard
ml-runtime-pbj-workbench-r4.5-standard
ml-runtime-pbj-workbench-scala2.12-standard
nemotron_nano_12b_v2_vl_v150
nim-baidu-paddleocr-v1.5.0
nim-bigcode-starcoder2-7b-v1.14.1
nim-bigcode-starcoder2-7b-v1.15.3
nim-deepseek-r1-v1.7.3
nim-meta-llama-3.1-nemotron-nano-8b-v1-v1.8.4
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0
nim-meta-llama3.1-70b-instruct-pb25h2-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.1-70b-instruct-v1.14.0
nim-meta-llama3.1-8b-instruct-v1.13.1
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.2-stig-fips-x86-64
nim-meta-llama3.1-8b-instruct-v1.14.0-pb5.5-stig-fips-x86-64
nim-meta-llama3.2-1b-instruct-v1.12.0
nim-meta-llama3.2-3b-instruct-v1.10.1
nim-meta-llama3.3-70b-instruct-v1.14.0
nim-meta-llama3.3-70b-instruct-v1.15.1
nim-minimax-ai-minimax-m25-v1.7.1
nim-mistralai-mistral-7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.12.0
nim-mistralai-mixtral-8x7b-instruct-v1.8.4
nim-mit-boltz2-v1.3.0
nim-mit-boltz2-v1.5.0
nim-nvidia-llama-3.1-nemotron-nano-4b-v1.1-v1.8.5
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.8.0
nim-nvidia-llama-3.2-nv-rerankqa-1b-v2-v1.9.3-stig-fips-x86
nim-nvidia-llama-3.3-nemotron-super-49b-v1-v1.10.1
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-pb25h2-v1.14.0
nim-nvidia-llama-3.3-nemotron-super-49b-v1.5-v1.14.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.10.0
nim-nvidia-llama-32-nv-embedqa-1b-v2-v1.11.3-stig-fips-x86
nim-nvidia-magpie-tts-multilingual-v1.6.0
nim-nvidia-nemoretriever-graphic-elements-v1-v1.6.0
nim-nvidia-nemoretriever-page-elements-v3-v1.7.0
nim-nvidia-nemoretriever-table-structure-v1-v1.6.0
nim-nvidia-nemotron-3-nano-v1.7.0
nim-nvidia-nemotron-3-super-120b-a12b-v1.8.1
nim-nvidia-nemotron-parse-v1.5.0
nim-nvidia-parakeet-1-1b-ctc-en-us-v1.4.0
nim-nvidia-whisper-large-v3-v1.3.0
nim-nvidia-whisper-large-v3-v1.4.0
nim-openai-gpt-oss-120b-v1.12.4
nim-openai-gpt-oss-20b-v1.12.4
python-runtime

CVE-2026-46331 In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.

dex-runtime-python-builder-7.1.9.1078-compat
python-runtime

CVE-2026-46862 Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-46863 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-47178 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-47247 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-47709 libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-47714 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a `width x height` bitmap. Version 1.22.0 patches the issue.

ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-48029 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-48779 ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

cdsw-web

CVE-2026-48864 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

dex-livy-runtime-2.4.8-7.1.9.1078
dex-livy-runtime-3.3.2-7.1.9.1078-compat
dex-livy-server-2.4.8-7.1.9.1078
dex-runtime-python-builder-7.1.9.1078-compat
dex-spark-history-server-2.4.8-7.1.9.1078
dex-spark-runtime-2.4.8-7.1.9.1078
dex-spark-runtime-3.3.2-7.1.9.1078-compat

CVE-2026-49295 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-49337 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-49346 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_image()` call computes the real size using `size_t`, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-50142 [Unknown description]

ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-52844 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy path-scoped auth/deny routes protecting /private/*. This vulnerability is fixed in 2.11.4.

cdwdataviz
runtimedataviz

CVE-2026-52845 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable. Result: a remote client can inject or sometimes override identity/group headers trusted by PHP/FastCGI applications behind Caddy. This vulnerability is fixed in 2.11.4.

cdwdataviz
runtimedataviz

CVE-2026-52846 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.

cdwdataviz
runtimedataviz

CVE-2026-53151 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a fragmented UDP packet (the packet would probably have to be deliberately pre-generated as fragmented) when AF_RXRPC tries to extract the contents of the SACK table by copying out the contents of the SACK table into a buffer before attempting to parse AF_RXRPC assumes that it can just call skb_condense() and then validly access the SACK table from skb->data and that it will be a flat buffer - but skb_condense() can silently fail to do anything under some circumstances. Note that whilst rxrpc_input_soft_acks() should be able to parse extended ACKs, the rest of AF_RXRPC doesn't currently support that. Further, there's then no need to call skb_condense() in rxrpc_input_ack(), so don't.

python-runtime

CVE-2026-53166 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

python-runtime

CVE-2026-53212 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_destroy() calls metadata_dst_free() which directly kfree()s the metadata_dst, ignoring the dst_entry refcount. Packets that took a reference via dst_hold() in nft_tunnel_obj_eval() and are still queued (e.g. in a netem qdisc) are left with a dangling pointer. When these packets are eventually dequeued, dst_release() operates on freed memory. Replace metadata_dst_free() with dst_release() so the metadata_dst is freed only after all references are dropped. The dst subsystem already handles metadata_dst cleanup in dst_destroy() when DST_METADATA is set.

python-runtime

CVE-2026-53215 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer. mvpp2_rx_refill() can fail after the current buffer has been handed to XDP or attached to an skb. In those cases mvpp2_run_xdp() may have recycled, redirected, or queued the page for XDP_TX, and an skb free also retires the data buffer. Returning such a buffer to BM lets hardware DMA into memory that is no longer owned by the RX ring. Refill the BM pool before handing the current buffer to XDP or to the skb. If the allocation fails there, drop the packet and return the still-owned current buffer to BM, preserving the pool depth. Once the refill succeeds, later local drops retire/free the current buffer instead of returning it to BM.

python-runtime

CVE-2026-53247 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_free_dev() calls metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace period. In the RX path, skb_dst_set_noref() sets a non-refcounted pointer from the skb to the metadata_dst. This function requires RCU read-side protection and the dst must remain valid until all RCU readers complete. Since metadata_dst_free() calls kfree() directly, a use-after-free can occur if any skb still holds a noref pointer to the dst when the driver tears it down. Replace metadata_dst_free() with dst_release() which properly goes through the refcount path: when the refcount drops to zero, it schedules the actual free via call_rcu_hurry(), ensuring all RCU readers have completed before the memory is freed.

python-runtime

CVE-2026-54240 CVE-2026-54240

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-54241 CVE-2026-54241

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-54285 opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerability is fixed in 2.8.0.

cdsw-web

CVE-2026-54911 No description available.

hue

CVE-2026-55199 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline
ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-55200 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

kserve_huggingfaceserver
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-r4.5-freshline

CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

ml-runtime-pbj-workbench-r4.5-standard

CVE-2026-58051 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

ml-runtime-pbj-workbench-r4.5-standard

GHSA-39q2-94rc-95cp ## Summary In `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation. The condition: ``` !(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])

cloudera-ai-agent-studio

GHSA-6v7q-wjvx-w8wg ## Summary basic-ftp's CRLF injection protection (added in commit 2ecc8e2 for GHSA-chqc-8p9q-pq6q) is incomplete. Two code paths bypass the `protectWhitespace()` control character check: (1) the `login()` method directly concatenates user-supplied credentials into USER/PASS FTP commands without any validation, and (2) the `_openDir()` method sends an MKD command before `cd()` invokes `protectWhitespace()`, creating a TOCTOU bypass. Both vectors allow an attacker who controls input to inject arbitrary FTP commands into the control connection. ## Details

cdsw-web

GHSA-76mc-f452-cxcm # Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` **CWE**: CWE-501 (Trust Boundary Violation — hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure — the default allow-list is silently widened for all subsequent sanitize calls) ## Summary

cloudera-ai-agent-studio

GHSA-8jr5-v98p-w75m ## Summary Issue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias. Issue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)

kserve_huggingfaceserver

GHSA-cj63-jhhr-wcxv ## Summary When `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when they are normally forbidden. The provided PoC sanitizes `<img onclick=...>` with `USE_PROFILES` and adds the sanitized output to the DOM; the polluted prototype allows the event handler to survive and execute, turning what should be a blocklist into a silent XSS vector. ## Impact Prototype pollution makes DOMPurify accept dangerous event handler attributes, which bypasses the sanitizer and results in DOM-based XSS once the sanitized markup is rendered.

cloudera-ai-agent-studio

GHSA-cjmm-f4jc-qw8r ## Summary DOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href="javascript:alert(document.domain)">` and have the `javascript:` URL survive, because URI validation is skipped for that attribute while other checks still pass. The provided PoC accepts `href` for anchors and then triggers a click inside an iframe, showing that the sanitized payload executes despite the protocol bypass. ## Impact Predicate-based allowlisting bypasses DOMPurify's URI validation, allowing unsafe protocols such as `javascript:` to reach the DOM and execute whenever the link is activated, resulting in DOM-based XSS.

cloudera-ai-agent-studio

GHSA-gr75-jv2w-4656 ## Summary Several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the *resolved* path to the intended root directory. Affected behaviors include: a file-search agent middleware that validates a starting directory but not the search pattern or the resolved target of matched files, so glob patterns and symlinks can reach files outside the configured root; prompt- and chain/agent-configuration loaders that accept path fields and resolve them without confining the result to a trusted base or rejecting symlink targets; and path-prefix authorization checks that compare by string prefix without a path-segment boundary, so a sibling path sharing the prefix is accepted. When these components receive path values, search patterns, or workspace contents influenced by an untrusted source — including an LLM acting on untrusted input — the result can be disclosure of files outside the intended boundary. We have no evidence of this behavior being triggered in the wild. ## Affected users / systems

ml-runtime-pbj-conda-standard
ml-runtime-pbj-jupyterlab-python3.10-cuda
ml-runtime-pbj-jupyterlab-python3.10-standard
ml-runtime-pbj-jupyterlab-python3.11-cuda
ml-runtime-pbj-jupyterlab-python3.11-freshline
ml-runtime-pbj-jupyterlab-python3.11-hardened
ml-runtime-pbj-jupyterlab-python3.11-standard
ml-runtime-pbj-jupyterlab-python3.12-cuda
ml-runtime-pbj-jupyterlab-python3.12-standard
ml-runtime-pbj-jupyterlab-python3.13-cuda
ml-runtime-pbj-jupyterlab-python3.13-standard
ml-runtime-pbj-jupyterlab-python3.14-hardened
ml-runtime-pbj-jupyterlab-r4.5-freshline

GHSA-gvmj-g25r-r7wr ## Summary When DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content. > **Note:** The string output path is **not** affected. Only the DOM return paths (`RETURN_DOM: true`, `RETURN_DOM_FRAGMENT: true`, `IN_PLACE: true`) are vulnerable.

cloudera-ai-agent-studio

GHSA-gx7w-56w6-g48x ## AI Disclosure I used an LLM to help review the source code, reason about attack surface, and help draft and refine this report. I manually validated the finding by reproducing it locally, confirming the vulnerable code path, and verifying the HTTP behavior with `curl -v`. ## Summary

cdwdataviz
runtimedataviz

GHSA-h8r8-wccr-v5f2 ## Description A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the PoC). ## Vulnerability

cloudera-ai-agent-studio

GHSA-vxr8-fq34-vvx9 ## Impact A DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration. If the old policy is unsafe or controlled by a less-trusted integration, this turns a later "default" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_POLICY: null` on the later call also does not clear the retained policy. [dompurify-trusted-types-policy-survives-clearconfig-poc.js](https://github.com/user-attachments/files/28604913/dompurify-trusted-types-policy-survives-clearconfig-poc.js)

cloudera-ai-agent-studio

GHSA-wwhq-w58m-w29c # ## TL;DR CVE-2026-30852 fixed double expansion in `vars_regexp` when the variable key is a placeholder (e.g. `{http.vars.x}`). The fix does NOT protect literal key names (e.g. `tenant_id`). An attacker injects `{env.AWS_SECRET_ACCESS_KEY}` or `{file./etc/passwd}` via a request header → Caddy expands it on the second pass → secrets leaked in response headers.

cdwdataviz
runtimedataviz

GHSA-x4vx-rjvf-j5p4 ## Summary When `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes. This affects current `3.4.6`. The recent `IN_PLACE` hardening work covers clobbered `form` handling and foreign-realm shadow/template traversal, but does not harden the main per-node element decision for hostile non-`form` live nodes.

cloudera-ai-agent-studio