Intel

AIKIDO-2025-10100

lightgbm is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-43598 Published Feb 17, 2025

75

High Risk

This Affects:

PYTHONlightgbm
2.0.2 - 4.5.0
Fixed in 4.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a forced heap-based buffer overflow when establishing a connection during distributed training initialization. An attacker can exploit this by sending a malicious rank through the listener, leading to an out-of-bounds write, which can result in remote code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

lightgbm is vulnerable to Remote Code Execution (RCE) in versions 2.0.2 - 4.5.0.

How to fix this

Upgrade the lightgbm library to the patch version.