-
CVE-2024-0139 – NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability (28 Nov 2024)
Preface: Nvidia acquires Bright Computing, maker of Bright Cluster Manager software that controls the configuration of clustered HPC systems, including Nvidia’s own DGX servers and HGX systems manufactured by OEMs and ODMs, as well as clusters from other manufacturers. Background: NVIDIA Base Command Manager provides cluster management software for streamlining cluster provisioning, workload management, and…
-
CVE-2024-0130: About design weakness on NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI (27 Nov 2024)
Preface: Artificial intelligence penetrates into different industries. Perhaps the expansion of some HPC supercomputers is not limited to regions. They can be run on a blockchain network to build a matrix. Background: In today’s high-performance computing (HPC) landscape, network interconnect technology is essential in linking compute nodes to ensure efficient data transfer. Among the interconnect…
-
CVE-2024-52811 : Fix heap buffer overflow writing not validated ACK to qlog (25 Nov 2024)
Preface: Most of Google’s traffic already goes through QUIC. Several other well-known companies have also begun developing their own implementations, such as Microsoft, Facebook, CloudFlare, Mozilla, Apple, Akamai,…etc Background: By combining the best of TCP and UDP, along with encryption and better handling of modern network conditions, QUIC is set to become the foundation of…
-
CVE-2024-11393 – Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability (25 Nov 2024)
Preface: What is the difference between Hugging Face and transformers? Transformers is a library that contains various state-of-the-art machine learning models, as well as a Trainer API which can be used to train models. Huggingface_hub is a library to programmatically integrate with the hub. Backgound: Masks are often used in segmentation tasks, where they provide…
-
CVE-2024-10382 – a code execution vulnerability in the Car App Android Jetpack Library (22 Nov 2024)
Preface: Android Auto is a platform running on the user’s phone, projecting the Android Auto user experience to a compatible in-vehicle infotainment system over a USB connection. Android Auto supports apps designed for in-vehicle use. Background: The Android for Cars App Library lets you bring your navigation, point of interest (POI), and internet of things…
-
CVE-2024-0122: About design weakness in NVIDIA Delegated Licensing Service (21nd Nov 2024)
Preface: NVIDIA Delegated License Service (DLS) is a component of NVIDIA License System that serves licenses to licensed clients. A DLS instance is hosted on-premises at a location that is accessible from your private network, such as inside your data center. Background: For deployment in a virtual machine, the Delegated License Server (DLS) component of…
-
CVE-2024-0138: NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component.
(Updated 11/18/2024 04:12 PM) Preface: Nvidia acquires Bright Computing, maker of Bright Cluster Manager software that controls the configuration of clustered HPC systems, including Nvidia’s own DGX servers and HGX systems manufactured by OEMs and ODMs, as well as clusters from other manufacturers. Background: NVIDIA Base Command Manager provides cluster management software for streamlining cluster…
-
CVE-2024-52316 : Unchecked Error Condition vulnerability in Apache Tomcat (19th Nov 2024)
Preface: Apache Tomcat is one of the top technologies in Java developers’ tech stacks—and for good reason. According to the 2024 Java Developer Productivity Report, 36% of Java developers use Apache Tomcat as their application server. Background: Apache Tomcat (called “Tomcat” for short) is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression…
-
CVE-2024-9413 – A vulnerability has been discovered in SCP-Firmware (18 Nov 2024)
Preface: The Cortex-M3 processor is specifically developed for high-performance, low-cost platforms for a broad range of devices including microcontrollers, automotive body systems, industrial control systems and wireless networking and sensors. Background: SCP Firmware provides a software reference implementation for the System Control Processor (SCP) and Manageability Control Processor (MCP) components found in several Arm Compute…
-
CVE-2024-28028: Improper input validation in some Intel® Neural Compressor software (15-11-2024)
Preface: If you talk to God, what is the difference between human and artificial intelligence? Maybe God will say that humans and A.I are incomparable. And both cannot live together in the same place. Background: Intel Neural Compressor performs model optimization to reduce the model size and increase the speed of deep learning inference for…