CVEs

Publicly disclosed vulnerabilities credited to me, grouped by vendor. Severity is the vendor’s own rating.

11 CVEs and 2 GitHub advisories across 7 vendors

Apple 2

  1. CVE-2026-64760 IOSurfaceAccelerator

    An app may be able to leak sensitive kernel state. Information leak, fixed with additional validation.

    Info leak

    AdvisoryNVD

  2. CVE-2026-28991 Accelerate

    An app may be able to cause a denial of service. Out-of-bounds read, fixed with improved bounds checking.

    OOB read

    AdvisoryNVD

Adobe 1

  1. CVE-2026-47911 Acrobat / Acrobat Reader

    Arbitrary code execution via an out-of-bounds write.

    Critical·OOB write·CWE-787·Windows and macOS, 26.001.21651 and earlier; Acrobat 2024 24.001.30365 and earlier·via ZDI

    AdvisoryNVD

NVIDIA 3

  1. CVE-2026-24268 TensorRT

    Code execution via a heap-based buffer overflow.

    High·Heap overflow·CWE-122·v10.16.1 and earlier, fixed in v11.0·via ZDI

    AdvisoryNVD

  2. CVE-2026-24238 TensorRT

    Code execution via improper validation of an array index.

    High·Index validation·CWE-129·v10.16.1 and earlier, fixed in v11.0·via ZDI

    AdvisoryNVD

  3. CVE-2026-24272 TensorRT

    Code execution via a heap-based buffer overflow.

    High·Heap overflow·CWE-122·v10.16.1 and earlier, fixed in v11.0·via ZDI

    AdvisoryNVD

llama.cpp 1

  1. CVE-2026-34159 llama.cpp

    Unauthenticated remote code execution. deserialize_tensor() skips bounds validation when a tensor’s buffer field is 0, giving arbitrary read/write of process memory via crafted GRAPH_COMPUTE messages; combined with pointer leaks this yields a full ASLR bypass.

    Critical·Arbitrary R/W·RPC backend, before b8492·via ggml

    AdvisoryNVD

ntop 1

  1. Stack-based buffer overflow in ndpi_address_cache_restore.

    High·Stack overflow·CWE-121·4.12 and earlier

    AdvisoryNVD

Open vSwitch / OVN 3

  1. CVE-2026-34956 Open vSwitch

    Remote denial of service. A crafted FTP stream with an EPASV command over 255 characters triggers a heap access error and crash.

    Medium·Remote DoS·CWE-120·Userspace datapath, conntrack FTP helper·via Red Hat

    AdvisoryNVD

  2. Heap memory disclosure to a VM. ICMP Destination Unreachable / Packet Too Big responses copy from the original packet using its self-declared IP length without checking the buffer size, so a short packet with an inflated length leaks heap contents.

    Medium·Info leak·CWE-130·ovn-controller ICMP error handling·via Red Hat

    AdvisoryNVD

  3. Heap memory disclosure to a VM. Crafted DHCPv6 SOLICIT packets with an inflated Client ID length cause an out-of-bounds read whose contents are returned to the attacker’s port.

    High·Info leak·CWE-130·ovn-controller DHCPv6·via Red Hat

    AdvisoryNVD

pupnp 2

  1. GHSA-mhhw-gm73-c57g pupnp (libupnp)

    Remote 1-byte heap over-read. A GENA SUBSCRIBE whose Callback header is missing its closing > makes create_url_list() and parse_uric() read one byte past a heap allocation.

    Moderate·OOB read·CWE-125·22.1.5 and earlier, fixed in 22.1.6

    GitHub advisory

  2. GHSA-ggw2-jjv9-h22c pupnp (libupnp)

    Remote out-of-bounds heap read in a control point. A malicious UPnP device sends a GENA NOTIFY with an oversized SID header, and GetClientSubActualSID() compares it with memcmp past the stored ID, reading up to about 16 KiB beyond a small heap allocation and crashing the control point.

    Moderate·OOB read·CWE-125·22.1.4 and earlier, fixed in 22.1.5

    GitHub advisory

Other acknowledgements 1

  1. The Omni GroupOmniGraffle for Mac

    Multiple vulnerabilities in PDF parsing and Microsoft Visio file handling. No CVE assigned; credited in the release notes.

    Fixed in 7.25.1, November 2025

    Release notes