Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-10-06
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-10-06
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-10-06
Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-10-06
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-10-06
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-10-06
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
CVSS Score
6.6
EPSS Score
0.001
Published
2026-10-06
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-10-06
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field, and wire-selected multimodal field processors without rebinding them to the active model renderer contract. Forged grid geometry, field types, or non-positive placeholder lengths can terminate the shared EngineCore; when an attacker knows or can induce a victim's content hash, forged cache hashes can poison or retrieve cross-request encoder-cache state; and dropped sparse placeholder masks can alter replayed transport semantics. This issue is fixed in version 0.30.0.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0.
CVSS Score
4.2
EPSS Score
0.002
Published
2026-10-05


Contact Us

Shodan ® - All rights reserved