#1150290 rccl: CVE-2026-43598

Package:
src:rccl
Source:
src:rccl
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 05:37:03 UTC
Severity:
normal
Tags:
#1150290#5
Date:
2026-10-08 05:35:08 UTC
From:
To:
Hi,

The following vulnerability was published for rccl.

CVE-2026-43598[0]:
| Improper input validation in the AMD ROCm Communication Collectives
| Library (RCCL) could allow a compromised peer rank or network-
| adjacent attacker to dereference an attacker-controlled pointer,
| potentially resulting in remote code execution.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-43598
https://www.cve.org/CVERecord?id=CVE-2026-43598
[1] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6033.html

Regards,
Salvatore