lightgbm@4.5.0 vulnerabilities

LightGBM Python Package

Direct Vulnerabilities

Known vulnerabilities in the lightgbm package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • C
Out-of-bounds Write

lightgbm is a gradient boosting framework that uses tree based learning algorithms.

Affected versions of this package are vulnerable to Out-of-bounds Write in linkers_socket.cpp, used during initialization of distributed training. An attacker can exploit a race condition to connect to a node while it is waiting for a legitimate connection from a configured peer, and send an arbitrary rank value. This may trigger an exploitable crash on the affected node.

How to fix Out-of-bounds Write?

A fix was pushed into the master branch but not yet published.

[0,)