Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6208

Опубликовано: 02 фев. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The SimpleDirectoryReader component in llama_index.core version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (num_files_limit) is applied after all files in a directory are loaded into memory. This can lead to memory exhaustion and degraded performance, particularly in environments with limited resources. The issue is resolved in version 0.12.41.

A flaw was found in llama_index. The SimpleDirectoryReader component loads all files from a specified directory into memory before applying a user-defined file limit. This resource management flaw allows an attacker to cause uncontrolled memory consumption. This can lead to memory exhaustion and degraded performance, resulting in a Denial of Service (DoS) for systems utilizing the affected component.

Отчет

This MODERATE impact flaw in llama_index affects Red Hat Ansible Automation Platform and OpenShift Lightspeed. The SimpleDirectoryReader component loads all files from a specified directory into memory before applying any user-defined file limits. This can lead to uncontrolled memory consumption, potentially causing a Denial of Service due to memory exhaustion and degraded performance in resource-constrained environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2435932llama_index: llama_index: Denial of Service due to uncontrolled memory consumption in SimpleDirectoryReader

EPSS

Процентиль: 5%
0.00019
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (`num_files_limit`) is applied after all files in a directory are loaded into memory. This can lead to memory exhaustion and degraded performance, particularly in environments with limited resources. The issue is resolved in version 0.12.41.

CVSS3: 5.3
github
2 месяца назад

llama-index-core vulnerable to Uncontrolled Resource Consumption

EPSS

Процентиль: 5%
0.00019
Низкий

5.3 Medium

CVSS3