BioNeMo Framework: Remote RCE via untrusted serialization
CVSS 8.8CVE-2026-24164NVIDIA / GPU stackcurated
Impact
Remote RCE via untrusted serialization
Who can reach it
Malicious model artifact / network payload
What to do
Bump BioNeMo; rebuild images
References
Related entries
- BioNeMo Framework: Arbitrary file read/write via path traversalCVE-2026-24217 · BioNeMo FrameworkHigh
- BioNeMo Framework: RCE via malicious pickled dataCVE-2026-24165 · BioNeMo FrameworkHigh
- BioNeMo Framework: RCE via insecure deserialization on model loadCVE-2026-24216 · BioNeMo FrameworkHigh
- NVIDIA FLARE SDK: RCE via unsafe deserialization in message handlingCVE-2026-24186 · NVIDIA FLARE SDKHigh
- GPU Display Driver: Local privesc to host root (use-after-free in context handling)CVE-2026-24187 · GPU Display DriverHigh
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): Memory is handed to a consumer without beingCVE-2026-53374 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.