NVIDIA FLARE SDK: RCE via unsafe deserialization in message handling
CVSS 8.8CVE-2026-24186NVIDIA / GPU stackcurated
Impact
RCE via unsafe deserialization in message handling
Who can reach it
Network peer in the federation
What to do
Upgrade FLARE; redeploy
References
Related entries
- NVIDIA FLARE SDK: Auth bypass via insufficient input validationCVE-2026-24204 · NVIDIA FLARE SDKMedium
- NVIDIA FLARE SDK: Unauthenticated remote code executionCVE-2026-24178 · NVIDIA FLARE SDKCritical
- GPU Display Driver: Local privesc to host root (use-after-free in context handling)CVE-2026-24187 · GPU Display DriverHigh
- BioNeMo Framework: Arbitrary file read/write via path traversalCVE-2026-24217 · BioNeMo FrameworkHigh
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): Memory is handed to a consumer without beingCVE-2026-53374 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
- Linux kernel amdgpu kernel driver core (drm/amdgpu/vce): A correctness defect in the amdgpu kernel driver coreCVE-2026-53375 · Linux kernel amdgpu kernel driver core (drm/amdgpu/vce)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.