NVIDIA Run:ai: Improper restriction of communication channels lets an attacker on an adjacent network reach
Impact
Improper restriction of communication channels lets an attacker on an adjacent network reach privilege escalation, data tampering and information disclosure in the Run:ai scheduler. Run:ai is the component deciding which tenant's job lands on which GPU, so control over it is control over the fleet's allocation and quota model.
Who can reach it
Adjacent network, low privileges, user interaction, high complexity. A tenant workload or a compromised pod inside the cluster network.
What to do
Upgrade Run:ai per bulletin 5719. Cost: a control-plane upgrade - the scheduler restarts, queued jobs pause, running jobs keep their GPUs. Plan it in a low-submission window rather than draining nodes.
References
Related entries
- TensorRT-LLM: DoS via large tensor allocationCVE-2026-24271 · TensorRT-LLMMedium
- TensorRT-LLM: DoS / memory corruption (insufficient tensor validation)CVE-2026-47470 · TensorRT-LLMMedium
- TensorRT-LLM: DoS via assertion failureCVE-2026-47475 · TensorRT-LLMMedium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Out-of-bounds array access in the escape handlerCVE-2021-1094 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An unprivileged local user gets limited write accessCVE-2022-21813 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)Medium
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An unprivileged local user gets limited write accessCVE-2022-21814 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.