CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library
Imported from official source
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identified CVE-2026-85228, an integer overflow in the tensor buffer validation component of DJL on all platforms. A crafted tensor payload declaring a shape whose computed byte size exceeds the 32-bit signed integer range causes the size to wrap, allowing an undersized buffer to pass validation; a subsequent tensor operation ...
This version
- Version
- 1 of 2
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
41b2ef0c35a60d8b0c1af502b4247b77- All versions
- Revision history