KAI Scheduler: Improper access control in resource allocation (cross-tenant quota abuse)
CVSS 4.3CVE-2026-24176NVIDIA / GPU stackcurated
Impact
Improper access control in resource allocation (cross-tenant quota abuse)
Who can reach it
Any tenant with cluster API access
What to do
Upgrade the KAI Scheduler Helm chart; rolling control-plane update, no tenant eviction
References
Related entries
- KAI Scheduler: Missing authentication on API endpointsCVE-2026-24177 · KAI SchedulerHigh
- Transformers4Rec: Code exec via insecure deserialization in the pipelineCVE-2026-24232 · Transformers4RecMedium
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- GeForce NOW Android app: Info disclosure / code exec via implicit intentCVE-2023-31014 · GeForce NOW Android appMedium
- DGX A100 SBIOS: Buffer overflow in SBIOSCVE-2023-31031 · DGX A100 SBIOSMedium
- Mellanox OS / MetroX / Onyx / Skyway: Improper access control on switch mgmtCVE-2024-0104 · Mellanox OS / MetroX / Onyx / SkywayMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.