Database/AI/ML frameworks & serving
NVIDIA NeMo Speech: malicious input data leads to remote code execution
Impact
A crafted data file processed by NeMo Speech gets the attacker code execution in the context of the process handling it, plus information disclosure and data tampering. On a GPU fleet that means whoever supplies a speech dataset or model artifact - a tenant, a data pipeline, an untrusted corpus - can run code inside the training or preprocessing job, with access to that job's credentials, mounted datasets and the GPUs assigned to it. NVIDIA scores it 7.8 local with user interaction required, so the realistic path is an operator or pipeline opening attacker-supplied data rather than a network-facing service. The record does not identify the vulnerable code path, so blast radius beyond the processing job is unestablished.
Who can reach it
No authentication to the toolkit itself; the attacker only needs to get a malicious data file in front of a NeMo Speech workflow. User interaction is required (someone must load the data), and the CVSS vector is local (AV:L).
What to do
Update NeMo Speech per NVIDIA security bulletin 2026/5885 and restart any jobs or services that use it. The record does not state a fixed version - read the bulletin for the exact release. Until updated, treat externally supplied speech datasets and manifests as untrusted input and process them in a sandboxed job with no cluster credentials mounted.
References
Related entries
- NVIDIA NeMo Speech: code injection from malicious input, no user interaction neededCVE-2026-65111 · NVIDIA NeMo SpeechHigh
- NVIDIA NeMo Speech: RCE and privilege escalation in the speech data explorerCVE-2026-24267 · NVIDIA NeMo Speech (speech data explorer)High
- BentoML (`safe_extract_tarfile`): Tar extraction escape despite the "safe" helperCVE-2026-27905 · BentoML (`safe_extract_tarfile`)High
- llama.cpp (`ggml_nbytes`): Integer overflow in the core ggml size calculationCVE-2026-33298 · llama.cpp (`ggml_nbytes`)High
- BentoML (`docker.system_packages`): Command injection through the package list fieldCVE-2026-33744 · BentoML (`docker.system_packages`)High
- BentoML (cloud deployment path, setup.sh generation in deployment.py): The March fix that added shlex.quote to theCVE-2026-35043 · BentoML (cloud deployment path, setup.sh generation in deployment.py)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.