VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

2026-09-14T20:52:02Z•04dd57a9f55ea16707469038f0c77c1aa96791d6bdb4af2a7d51595ddc9ae3b3
CVE-2025-20701CVE-2026-12780CVE-2026-15630CVE-2026-80047CVE-2026-84282CVE-2026-84286AOMEI-BackupperBluetoothCERT/CCCUDACasdoorExLlamaV3Hugging-Face-TransformersONLYOFFICESSRFSecure-BootSkullcandy-Dime-3UEFIauthorization-bypassdenial-of-servicefirmwarekernel-driverlocal-privilege-escalationmulti-tenancyownCloudremote-codesupply-chainunauthenticated-pairingvulnerability-disclosure

What happened

CERT/CC vulnerability notes covering seven vulnerabilities disclosed in September 2026: denial of service in ExLlamaV3 CUDA kernel dispatch, local privilege escalation and pre-boot compromise via AOMEI Backupper's kernel driver, Secure Boot bypass involving embedded UEFI Shell modules, unauthenticated Bluetooth pairing in Skullcandy Dime 3 earbuds, SSRF in the ONLYOFFICE ownCloud integration, cross-tenant authorization bypass in Casdoor, and unauthorized local caching of remote Python code in Hugging Face Transformers.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
04dd57a9f55ea16707469038f0c77c1aa96791d6bdb4af2a7d51595ddc9ae3b3
Enrichment time
2026-09-14T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.