VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
2026-09-15T20:52:02Z•fd2402b79b447edc18f2a3b62b130faf86f48bcb8bb84acb111d53593646d8e1
CVE-2025-20701CVE-2026-12780CVE-2026-15630CVE-2026-80047CVE-2026-84282CVE-2026-84286AOMEI-BackupperBluetoothCERT/CCCUDACasdoorExLlamaV3Hugging-FaceSSRFSecure-Boot-bypassUEFIarbitrary-disk-writeauthentication-bypassauthorization-bypassdenial-of-servicelocal-privilege-escalationmachine-learningmulti-tenancyout-of-bounds-memory-accessownCloudremote-code-loadingsupply-chainvulnerability-disclosure
What happened
CERT/CC vulnerability notes disclose multiple 2026 vulnerabilities affecting ExLlamaV3, AOMEI Backupper, UEFI firmware implementations, Skullcandy Dime 3 earbuds, the ONLYOFFICE ownCloud plugin, Casdoor, and Hugging Face Transformers. Impacts include denial of service, local-to-UEFI privilege escalation, Secure Boot bypass, unauthorized Bluetooth pairing, SSRF, cross-tenant authorization bypass, and unauthorized writing of remote Python code to disk. Vendors or maintainers have remediation guidance for some issues; affected deployments should apply available fixes and review exposure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- fd2402b79b447edc18f2a3b62b130faf86f48bcb8bb84acb111d53593646d8e1
- Enrichment time
- 2026-09-15T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.