{"vuid":"VU#369611","idnumber":"369611","name":"ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index","keywords":null,"overview":"### Overview\r\nAn out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the `exllamav3_ext` compute unified device architecture (`CUDA`) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286.\r\n\r\n### Description\r\nAn OOB memory access vulnerability exists in the `exllamav3_ext` module due to insufficient input validation.\r\n\r\nWhen the kernel parameter `K` is set to 0 in a crafted input, the extension generates a negative array index, resulting in a `CUDA` illegal memory access.s. The root cause is a missing bounds check in the kernel-table dispatch process. The checkpoint-derived block index (`cbi`) is used to access a fixed 24-entry array without confirming that either `K` or `cbi` fall within safe limits.\r\n\r\n### Impact\r\nPrimary impacts include Denial of Service (DoS) through process crashes and potential unstable execution states within applications utilizing the library.\r\n\r\n### Solution\r\nThe vendor has addressed this vulnerability in the main repository. Users are advised to update their installations or apply the fix from the merged pull request: https://github.com/turboderp-org/exllamav3/pull/310. \r\n\r\n### Supply chain\r\nDownstream projects utilizing this library are indirectly exposed to this vulnerability. According to the `ExLlamaV3` Dependency Graph, there are 49 total dependencies currently tracking this repository. Notable downstream projects directly affected by this supply chain link include: `UnstableLlama` / `ezexl3` and `Ednaordinary` / `MawDiscord`\r\nDevelopers and maintainers of these dependent repositories are strongly encouraged to rebuild their packages against the patched version of `exllamav3_ext`.\r\n\r\n### Acknowledgements\r\nThe CERT Coordination Center (CERT/CC) thanks Nathan Keys (professor-moody) for discovering and responsibly reporting this vulnerability.\r\nThis AI-assisted vulnerability note was prepared by Laurie Tyzenhaus.","clean_desc":null,"impact":null,"resolution":null,"workarounds":null,"sysaffected":null,"thanks":null,"author":null,"public":[],"cveids":["CVE-2026-84286"],"certadvisory":null,"uscerttechnicalalert":null,"datecreated":"2026-09-11T20:11:37.854255Z","publicdate":"2026-09-11T20:11:37.732697Z","datefirstpublished":"2026-09-11T20:11:37.865781Z","dateupdated":"2026-09-11T20:11:37.732692Z","revision":1,"vrda_d1_directreport":null,"vrda_d1_population":null,"vrda_d1_impact":null,"cam_widelyknown":null,"cam_exploitation":null,"cam_internetinfrastructure":null,"cam_population":null,"cam_impact":null,"cam_easeofexploitation":null,"cam_attackeraccessrequired":null,"cam_scorecurrent":null,"cam_scorecurrentwidelyknown":null,"cam_scorecurrentwidelyknownexploited":null,"ipprotocol":null,"cvss_accessvector":null,"cvss_accesscomplexity":null,"cvss_authentication":null,"cvss_confidentialityimpact":null,"cvss_integrityimpact":null,"cvss_availabilityimpact":null,"cvss_exploitablity":null,"cvss_remediationlevel":null,"cvss_reportconfidence":null,"cvss_collateraldamagepotential":null,"cvss_targetdistribution":null,"cvss_securityrequirementscr":null,"cvss_securityrequirementsir":null,"cvss_securityrequirementsar":null,"cvss_basescore":null,"cvss_basevector":null,"cvss_temporalscore":null,"cvss_environmentalscore":null,"cvss_environmentalvector":null,"metric":null,"vulnote":245}