Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
2026-05-11T01:24:04Z•8aa222e2e7afc24098c79a9401bc59853985f6b48f084e8a3753dda36ce60ea4
Apache HTTP/2Bleeding LlamaCVE-2026-0300CVE-2026-23918CVE-2026-29201CVE-2026-31431CVE-2026-6973DAEMON ToolsDirty FragIvanti EPMMLinux LPEMirai/xlabs_v1 botnetOllamaPAN-OSPalo AltoPyPI malwareTCLBANKERZiChatBotbanking trojancPanelmemory leakout-of-bounds readsandbox escapesupply chain compromisevm2
What happened
This collection of The Hacker News items highlights multiple high-impact security issues and active threats. Notable disclosures include a critical Ollama out-of-bounds read (Bleeding Llama) — CVE-2026-7482 — enabling remote process memory disclosure (CVSS 9.1); active exploitation of a PAN-OS buffer overflow allowing unauthenticated RCE (CVE-2026-0300); a severe Apache HTTP/2 double-free with possible RCE (CVE-2026-23918); and a set of critical vm2 sandbox-escape vulnerabilities in Node.js. Other important items: a new Linux local privilege escalation (“Dirty Frag”) related to CVE-2026-31431,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8aa222e2e7afc24098c79a9401bc59853985f6b48f084e8a3753dda36ce60ea4
- Enrichment time
- 2026-05-11T01:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.