[Git][security-tracker-team/security-tracker][master] Add CVE-2026-5497/vllm

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jun 11 21:21:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
580c3915 by Salvatore Bonaccorso at 2026-06-11T22:19:14+02:00
Add CVE-2026-5497/vllm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32,7 +32,7 @@ CVE-2026-6277 (GitLab has remediated an issue in GitLab EE affecting all version
 CVE-2026-6269 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	- gitlab <removed>
 CVE-2026-5497 (vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) ...)
-	TODO: check
+	- vllm <itp> (bug #1095237)
 CVE-2026-53912 (Cerebrate before version 1.37 exposed credential material from self-re ...)
 	NOT-FOR-US: Cerebrate
 CVE-2026-53911 (Cerebrate before version 1.37 allowed the id primary key field to be s ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580c3915837ea92e87ea9c8ed6e201209a16f7fb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580c3915837ea92e87ea9c8ed6e201209a16f7fb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260611/8618a70c/attachment.htm>


More information about the debian-security-tracker-commits mailing list