PulseAugur
中
实时 05:03:14
English(EN) 🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in its model loader: CVE-2026-102566 (CVSS 7.

CTranslate2推理引擎易受代码执行和内存泄露攻击

在CTranslate2中发现了两个关键漏洞,CVE-2026-102566和CVE-2026-102567。CTranslate2是Whisper和OpenNMT使用的推理引擎。这些与模型加载器相关的缺陷在加载恶意模型文件时可能导致任意代码执行或内存泄露/崩溃。这些漏洞影响4.8.1之前的所有版本,建议用户更新到已修复的版本。 AI

影响 CTranslate2中的关键漏洞可能使AI模型和系统面临安全风险,需要及时修补。

排序理由 识别出AI推理引擎中的漏洞,这是一个软件工具。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

CTranslate2推理引擎易受代码执行和内存泄露攻击

本文如何被排名

Signal score
4 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
识别出AI推理引擎中的漏洞,这是一个软件工具。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
infra, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 Whisper & OpenNMT背后的推理引擎在其模型加载器中存在两个内存缺陷:CVE-2026-102566(CVSS 7.

    🚨 CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in its model loader: CVE-2026-102566 (CVSS 7.8) — heap buffer overflow → arbitrary code execution CVE-2026-102567 (CVSS 6.1) — OOB read → memory disclosure / crash A…