Libxsmm is a specialized matrix-multiplication library optimized for high-performance computing and deep-learning workloads, with a narrow product footprint but deep integration into scientific and machine-learning software stacks. Its vulnerability surface centers on memory-safety and resource-handling issues—out-of-bounds writes, buffer boundary violations, NULL-pointer dereferences, and uncontrolled resource consumption—that are characteristic of performance-critical numerical code. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libxsmm Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20541HIGH There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a di | Dec 28, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-20542HIGH There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is | Dec 28, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-39536HIGH An issue was discovered in libxsmm through v1.16.1-93. The JIT code has a heap-based buffer overflow. | Sep 20, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-39535MEDIUM An issue was discovered in libxsmm through v1.16.1-93. A NULL pointer dereference exists in JIT code. It allows an attacker to cause Denial of Service. | Sep 20, 2021 | 6.5 | 21 | NO | NO |
CVE-2018-20543MEDIUM There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will cause a denial of service. | Dec 28, 2018 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libxsmm Project.
Media articles that mention a CVE ID that affects a product developed by Libxsmm Project — matched by CVE ID, not by vendor name.