Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

2026-05-10T19:24:11Zbecb6b42501d3408c507dd8587f0bd4c833e224741d0e966c82e27789aed95b3
backdoorbleeding_llamabotnetcloudcredential-theftexploithigh-riskincident-responselinuxlpemalwarememory-leaknodejspythonrcesupply-chaintrojanvendor-patchvulnerabilityworm

What happened

Multiple high‑impact vulnerabilities and active malware campaigns were reported across open‑source and commercial software. Notable disclosures include an out‑of‑bounds read in Ollama (CVE-2026-7482, “Bleeding Llama”, CVSS 9.1) that can leak process memory and may affect ~300,000 servers; a PAN-OS buffer‑overflow RCE under active exploitation (CVE-2026-0300, CVSS ~9.3); an Apache HTTP/2 double‑free (CVE-2026-23918) with potential RCE; Ivanti EPMM RCE exploited in the wild (CVE-2026-6973); and cPanel/WHM fixes (including CVE-2026-29201). Additional threats include a new Linux LPE (“Dirty Frag,”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
becb6b42501d3408c507dd8587f0bd4c833e224741d0e966c82e27789aed95b3
Enrichment time
2026-05-10T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak · Baitaphish