GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Megatron-LM: crafted input files execute attacker code in training and evaluation scripts

CVSS 7.8CVE-2025-23348NVIDIA / GPU stack+3 more CVEscurated

Impact

Loading an attacker-supplied data or checkpoint file makes a Megatron-LM script execute the attacker's code with the training job's privileges - typically a GPU, a service account, and mounted object-storage credentials. NVIDIA split the same flaw across 4 ids, one per affected script (pretrain_gpt, tasks/orqa/unsupervised/nq.py, the msdp preprocessing script, and ensemble_classifier); an operator's exposure and response are identical for all of them.

Who can reach it

Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.

What to do

Bump Megatron-LM to the fixed version in NVIDIA bulletin 5698 and rebuild every training/inference image that embeds it - one upgrade covers all 4 ids. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints and corpora at all: prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.

Also covers 3 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2025-23349CVE-2025-23353CVE-2025-23354

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.