NVIDIA Megatron-LM: crafted input files execute attacker code in training and evaluation scripts
Impact
Loading an attacker-supplied data or checkpoint file makes a Megatron-LM script execute the attacker's code with the training job's privileges - typically a GPU, a service account, and mounted object-storage credentials. NVIDIA split the same flaw across 4 ids, one per affected script (pretrain_gpt, tasks/orqa/unsupervised/nq.py, the msdp preprocessing script, and ensemble_classifier); an operator's exposure and response are identical for all of them.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump Megatron-LM to the fixed version in NVIDIA bulletin 5698 and rebuild every training/inference image that embeds it - one upgrade covers all 4 ids. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints and corpora at all: prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
Also covers 3 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA Megatron-LM: A script in the repository injects code from crafted dataCVE-2025-23357 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: A further script-level code-injection path, filed under the same class as the 2025 setCVE-2026-24149 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: Checkpoint loading reaches remote code execution when a user loads a crafted checkpointCVE-2026-24150 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: The inferencing path reaches remote code execution on crafted inputCVE-2026-24151 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: A second checkpoint-loading remote code execution pathCVE-2026-24152 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: A code-injection flaw in the tools component executes attacker-controlled code inside the trainingCVE-2025-23305 · NVIDIA Megatron-LMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.