AINewsnow

Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

A crafted TCP packet to Mooncake's transfer data port is enough to read and write arbitrary process memory — no authentication required. CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The readHeader function trusts attacker-supplied addr and size fields…

Read the full story at DEV Community — Machine Learning ↗

Timeline · 1 report

  1. 2026-10-02 03:15 · DEV Community — Machine Learning
    Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

More stories

  1. Bring near-Astra intelligence to everyday work with GPT-6.1 Sol on Amazon Bedrock — AWS Machine Learning Blog
  2. Gemini 4 Argon: our next era of frontier intelligence — Google Gemini Blog
  3. Introducing Olmo-core 3: Open, scalable training infrastructure for large MoEs — Allen Institute for AI (Ai2)
  4. Google Releases New Gemini Model With Guardrails Amid A.I. Safety Debate — New York Times Technology
  5. OpenAI postpones release of latest AI model over security concerns as the industry faces new safety pressures — Euronews Next
  6. Introducing GPT-6.1 Sol — OpenAI News
  7. Google tests its plan for AI data centers in space with Project Suncatcher — Scientific American
  8. OpenAI’s Dots Are Always-On AI Agents—and Its Answer to Meta’s Muse — Wired AI

Get the daily brief of stories like this at 6:30 every morning →