NVIDIA TensorRT: An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with no
Impact
An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with no privileges required. TensorRT sits inside almost every optimised inference deployment, so the affected surface is wide even where TensorRT is not the thing you deployed by name.
Who can reach it
Network, unauthenticated. Reached through whatever service embeds the TensorRT runtime and passes it externally-influenced input.
What to do
Update TensorRT per bulletin 5836 and rebuild every inference image that links it - including Triton images with the TensorRT backend. Cost: image rebuild plus rolling restart; inventory work is the expensive part because TensorRT is usually a transitive dependency.
References
Related entries
- NVIDIA CUDA-Q: Info disclosure / code exec (OOB read in circuit compilation)CVE-2026-24189 · NVIDIA CUDA-QHigh
- NVIDIA Dynamo: RCE via buffer overflow in tensor shape validationCVE-2026-24253 · NVIDIA DynamoHigh
- DCGM: DoS of the GPU telemetry/health daemon (resource exhaustion)CVE-2026-47483 · DCGMHigh
- NVIDIA Dynamo: Deserialization of untrusted data in Dynamo reaches denial of service and data tamperingCVE-2026-47623 · NVIDIA DynamoHigh
- DGX servers BMC: RCE on BMC (buffer overflow)CVE-2022-42272 · DGX servers BMCHigh
- DGX servers BMC: RCE on BMC (buffer overflow)CVE-2022-42273 · DGX servers BMCHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.