Beveiligingsadvies

CVE-2026-92786

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 20:32:43
Laatst bijgewerkt 2026-09-16 20:32:43
Toegewezen door VulnCheck
CVSS-score 8.5
Status PUBLISHED

Beschrijving

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.