Description
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.
Published: 2026-09-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Deserialization
Action: Apply Patch Immediately
AI Analysis

Impact

A deserialization vulnerability exists in tile-lang's KernelCache._load_kernel_from_disk function, allowing an attacker to manipulate serialized data that is read from disk. Exploiting this flaw could enable remote execution of arbitrary code or other malicious actions depending on how the deserialized objects are used by the application. The flaw is rooted in improper input validation and insecure deserialization practices.

Affected Systems

The vulnerability affects versions of tile-ai tilelang up to 0.1.14. No other vendors or products are mentioned. Users running 0.1.14 or earlier are at risk.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the flaw is not listed in CISA's KEV catalog, which suggests limited known exploitation attempts so far. However, the description confirms that the attack can be performed from remote, so an attacker who can influence the data stored for the kernel cache could trigger the vulnerable deserialization path. Given the medium CVSS score and lack of active exploitation evidence, organizations should treat this as an important but not urgent issue, applying the vendor patch as soon as it is released.

Generated by OpenCVE AI on September 9, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update tile-lang to a version that includes the commit 11ec2397fe942e8b422d026af4a03d6e0a55ae6c or later, once it is released by tile-ai.
  • If an immediate update is not possible, use the identified patch directly from the repository or downgrade to a pre‑vulnerability version if available.
  • Limit exposure of the _load_kernel_from_disk function by restricting which files and directories can be read for kernel deserialization, ensuring only trusted, internal sources are used.

Generated by OpenCVE AI on September 9, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.
Title tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
First Time appeared Tile-ai
Tile-ai tilelang
Weaknesses CWE-20
CWE-502
CPEs cpe:2.3:a:tile-ai:tilelang:*:*:*:*:*:*:*:*
Vendors & Products Tile-ai
Tile-ai tilelang
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Tile-ai Tilelang
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-09T15:38:14.232Z

Reserved: 2026-09-08T19:23:59.560Z

Link: CVE-2026-87083

cve-icon Vulnrichment

Updated: 2026-09-09T15:38:10.066Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T02:16:57.100

Modified: 2026-09-09T16:17:14.890

Link: CVE-2026-87083

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T01:15:11Z

Links: CVE-2026-87083 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:15:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-502

    Deserialization of Untrusted Data