CVEs
Publicly disclosed vulnerabilities credited to me, grouped by vendor. Severity is the vendor’s own rating.
11 CVEs and 2 GitHub advisories across 7 vendors
Apple 2
-
CVE-2026-64760 IOSurfaceAccelerator
An app may be able to leak sensitive kernel state. Information leak, fixed with additional validation.
Info leak
-
CVE-2026-28991 Accelerate
An app may be able to cause a denial of service. Out-of-bounds read, fixed with improved bounds checking.
OOB read
Adobe 1
-
CVE-2026-47911 Acrobat / Acrobat Reader
Arbitrary code execution via an out-of-bounds write.
Critical·OOB write·CWE-787·Windows and macOS, 26.001.21651 and earlier; Acrobat 2024 24.001.30365 and earlier·via ZDI
NVIDIA 3
-
CVE-2026-24268 TensorRT
Code execution via a heap-based buffer overflow.
High·Heap overflow·CWE-122·v10.16.1 and earlier, fixed in v11.0·via ZDI
-
CVE-2026-24238 TensorRT
Code execution via improper validation of an array index.
High·Index validation·CWE-129·v10.16.1 and earlier, fixed in v11.0·via ZDI
-
CVE-2026-24272 TensorRT
Code execution via a heap-based buffer overflow.
High·Heap overflow·CWE-122·v10.16.1 and earlier, fixed in v11.0·via ZDI
llama.cpp 1
-
CVE-2026-34159 llama.cpp
Unauthenticated remote code execution.
deserialize_tensor()skips bounds validation when a tensor’s buffer field is 0, giving arbitrary read/write of process memory via craftedGRAPH_COMPUTEmessages; combined with pointer leaks this yields a full ASLR bypass.Critical·Arbitrary R/W·RPC backend, before b8492·via ggml
ntop 1
-
CVE-2025-25066 nDPI
Stack-based buffer overflow in
ndpi_address_cache_restore.High·Stack overflow·CWE-121·4.12 and earlier
Open vSwitch / OVN 3
-
CVE-2026-34956 Open vSwitch
Remote denial of service. A crafted FTP stream with an
EPASVcommand over 255 characters triggers a heap access error and crash.Medium·Remote DoS·CWE-120·Userspace datapath, conntrack FTP helper·via Red Hat
-
CVE-2026-5265 OVN
Heap memory disclosure to a VM. ICMP Destination Unreachable / Packet Too Big responses copy from the original packet using its self-declared IP length without checking the buffer size, so a short packet with an inflated length leaks heap contents.
Medium·Info leak·CWE-130·ovn-controller ICMP error handling·via Red Hat
-
CVE-2026-5367 OVN
Heap memory disclosure to a VM. Crafted DHCPv6
SOLICITpackets with an inflated Client ID length cause an out-of-bounds read whose contents are returned to the attacker’s port.High·Info leak·CWE-130·ovn-controller DHCPv6·via Red Hat
pupnp 2
-
GHSA-mhhw-gm73-c57g pupnp (libupnp)
Remote 1-byte heap over-read. A GENA SUBSCRIBE whose
Callbackheader is missing its closing>makescreate_url_list()andparse_uric()read one byte past a heap allocation.Moderate·OOB read·CWE-125·22.1.5 and earlier, fixed in 22.1.6
-
GHSA-ggw2-jjv9-h22c pupnp (libupnp)
Remote out-of-bounds heap read in a control point. A malicious UPnP device sends a GENA NOTIFY with an oversized
SIDheader, andGetClientSubActualSID()compares it withmemcmppast the stored ID, reading up to about 16 KiB beyond a small heap allocation and crashing the control point.Moderate·OOB read·CWE-125·22.1.4 and earlier, fixed in 22.1.5
Other acknowledgements 1
-
The Omni GroupOmniGraffle for Mac
Multiple vulnerabilities in PDF parsing and Microsoft Visio file handling. No CVE assigned; credited in the release notes.
Fixed in 7.25.1, November 2025