VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

2026-09-15T20:52:02Z•fd2402b79b447edc18f2a3b62b130faf86f48bcb8bb84acb111d53593646d8e1
CVE-2025-20701CVE-2026-12780CVE-2026-15630CVE-2026-80047CVE-2026-84282CVE-2026-84286AOMEI-BackupperBluetoothCERT/CCCUDACasdoorExLlamaV3Hugging-FaceSSRFSecure-Boot-bypassUEFIarbitrary-disk-writeauthentication-bypassauthorization-bypassdenial-of-servicelocal-privilege-escalationmachine-learningmulti-tenancyout-of-bounds-memory-accessownCloudremote-code-loadingsupply-chainvulnerability-disclosure

What happened

CERT/CC vulnerability notes disclose multiple 2026 vulnerabilities affecting ExLlamaV3, AOMEI Backupper, UEFI firmware implementations, Skullcandy Dime 3 earbuds, the ONLYOFFICE ownCloud plugin, Casdoor, and Hugging Face Transformers. Impacts include denial of service, local-to-UEFI privilege escalation, Secure Boot bypass, unauthorized Bluetooth pairing, SSRF, cross-tenant authorization bypass, and unauthorized writing of remote Python code to disk. Vendors or maintainers have remediation guidance for some issues; affected deployments should apply available fixes and review exposure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
fd2402b79b447edc18f2a3b62b130faf86f48bcb8bb84acb111d53593646d8e1
Enrichment time
2026-09-15T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.