Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
2026-05-10T19:24:11Z•becb6b42501d3408c507dd8587f0bd4c833e224741d0e966c82e27789aed95b3
backdoorbleeding_llamabotnetcloudcredential-theftexploithigh-riskincident-responselinuxlpemalwarememory-leaknodejspythonrcesupply-chaintrojanvendor-patchvulnerabilityworm
What happened
Multiple high‑impact vulnerabilities and active malware campaigns were reported across open‑source and commercial software. Notable disclosures include an out‑of‑bounds read in Ollama (CVE-2026-7482, “Bleeding Llama”, CVSS 9.1) that can leak process memory and may affect ~300,000 servers; a PAN-OS buffer‑overflow RCE under active exploitation (CVE-2026-0300, CVSS ~9.3); an Apache HTTP/2 double‑free (CVE-2026-23918) with potential RCE; Ivanti EPMM RCE exploited in the wild (CVE-2026-6973); and cPanel/WHM fixes (including CVE-2026-29201). Additional threats include a new Linux LPE (“Dirty Frag,”
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- becb6b42501d3408c507dd8587f0bd4c833e224741d0e966c82e27789aed95b3
- Enrichment time
- 2026-05-10T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.