NVIDIA NVTabular: The Workflow component deserializes untrusted data, reaching code execution
Impact
The Workflow component deserializes untrusted data, reaching code execution. Feature-engineering workflows are commonly shared as artifacts, which is the delivery path. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5739 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- BioNeMo Framework: Remote RCE via untrusted serializationCVE-2026-24164 · BioNeMo FrameworkHigh
- NVIDIA FLARE SDK: RCE via unsafe deserialization in message handlingCVE-2026-24186 · NVIDIA FLARE SDKHigh
- GPU Display Driver: Local privesc to host root (use-after-free in context handling)CVE-2026-24187 · GPU Display DriverHigh
- BioNeMo Framework: Arbitrary file read/write via path traversalCVE-2026-24217 · BioNeMo FrameworkHigh
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): Memory is handed to a consumer without beingCVE-2026-53374 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
- Linux kernel amdgpu kernel driver core (drm/amdgpu/vce): A correctness defect in the amdgpu kernel driver coreCVE-2026-53375 · Linux kernel amdgpu kernel driver core (drm/amdgpu/vce)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.