VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
2026-09-14T20:52:02Z•04dd57a9f55ea16707469038f0c77c1aa96791d6bdb4af2a7d51595ddc9ae3b3
CVE-2025-20701CVE-2026-12780CVE-2026-15630CVE-2026-80047CVE-2026-84282CVE-2026-84286AOMEI-BackupperBluetoothCERT/CCCUDACasdoorExLlamaV3Hugging-Face-TransformersONLYOFFICESSRFSecure-BootSkullcandy-Dime-3UEFIauthorization-bypassdenial-of-servicefirmwarekernel-driverlocal-privilege-escalationmulti-tenancyownCloudremote-codesupply-chainunauthenticated-pairingvulnerability-disclosure
What happened
CERT/CC vulnerability notes covering seven vulnerabilities disclosed in September 2026: denial of service in ExLlamaV3 CUDA kernel dispatch, local privilege escalation and pre-boot compromise via AOMEI Backupper's kernel driver, Secure Boot bypass involving embedded UEFI Shell modules, unauthenticated Bluetooth pairing in Skullcandy Dime 3 earbuds, SSRF in the ONLYOFFICE ownCloud integration, cross-tenant authorization bypass in Casdoor, and unauthorized local caching of remote Python code in Hugging Face Transformers.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 04dd57a9f55ea16707469038f0c77c1aa96791d6bdb4af2a7d51595ddc9ae3b3
- Enrichment time
- 2026-09-14T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.