NVIDIA Isaac Lab: A deserialization flaw reaches code execution
Impact
A deserialization flaw reaches code execution; scored 9.0 network with a changed scope. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5733 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- Apex: Remote RCE via unsafe pickle deserializationCVE-2025-33244 · ApexCritical
- NVIDIA BlueField - VIRTIO-Net emulation: A VM user sends a crafted message to the BlueField VIRTIO-Net device and getsCVE-2026-65094 · NVIDIA BlueField - VIRTIO-Net emulationCritical
- ConnectX / BlueField firmware: Improper certificate validationCVE-2024-0105 · ConnectX / BlueField firmwareHigh
- NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device node: The GPU-side twin ofCVE-2012-0946 · NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device nodeHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Any local account on a Windows GPU host can call the driver's escapeCVE-2018-6247 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel read/write from an unprivileged escape callCVE-2018-6248 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.