Impact
A flaw in the Triton dequantization kernel of ModelCloud GPTQModel allows an attacker to manipulate the argument g_idx, causing an out‑of‑bounds read. The vulnerability can be triggered remotely and may enable an adversary to read memory beyond the intended buffer, potentially exposing sensitive data. The cross‑boundary memory access results in an information‑disclosure risk rather than a direct code execution vector.
Affected Systems
ModelCloud GPTQModel products with versions up to 7.2.0 are affected. The fix was applied in the 7.3.0 release, described by patch commit 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. All users of the gptqmodel/nn_modules/qlinear/tritonv2.py component in those version ranges should verify they are not running the vulnerable code.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, but the exploit has been publicly disclosed and can be executed remotely. Attackers could exploit the remote read vulnerability in environments that expose the Triton dequantization service to the network, leading to potential leakage of confidential data.
OpenCVE Enrichment