RAPIDS cuDF / cuML: RCE via unsafe deserialization
CVSS 6.8CVE-2024-0140NVIDIA / GPU stackcurated
Impact
RCE via unsafe deserialization
Who can reach it
Malicious model/dataset artifact loaded by a tenant job
What to do
Bump RAPIDS packages; rebuild data-science base images
References
Related entries
- Hopper HGX 8-GPU: DoS (inadequate loop termination in firmware)CVE-2024-0141 · Hopper HGX 8-GPUMedium
- nvJPEG2000: Code exec via OOB write on malicious imageCVE-2024-0142 · nvJPEG2000Medium
- nvJPEG2000: Code exec via OOB writeCVE-2024-0143 · nvJPEG2000Medium
- nvJPEG2000: Code exec via buffer overflowCVE-2024-0144 · nvJPEG2000Medium
- nvJPEG2000: Code exec via heap overflowCVE-2024-0145 · nvJPEG2000Medium
- SNAP-4 container (BlueField storage): DoS of the storage dataplaneCVE-2025-33215 · SNAP-4 container (BlueField storage)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.