CVE-2026-87083: tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache.loadkernelfromdisk of the file tilelang/cache/kernelcache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserializationto a version that resolves this vulnerability.Patch 11ec2397fe942e8b422d026af4a03d6e0a55ae6c
Event History
Frequently Asked Questions
Which versions are affected, and is a fixed release available?
tile-ai/tilelang versions up to 0.1.14 are affected. The fix is identified as commit 11ec2397fe942e8b422d026af4a03d6e0a55ae6c, but it has not been included in an official release.
What level of access or interaction is required for exploitation?
The issue can be exploited remotely with low attack complexity, but the attacker requires low-level privileges and user interaction. The provided data does not specify what form that privilege or interaction takes.
What should teams do if they cannot wait for an official release?
Apply patch 11ec2397fe942e8b422d026af4a03d6e0a55ae6c where feasible. The available information does not provide a separate configuration workaround or mitigation.