Database/AI/ML frameworks & serving
NVIDIA OpenShell for Linux: improper output encoding in the inference proxy leaks data and allows tampering
Impact
The flaw is in the inference proxy - the component that sits between callers and the model endpoint - so anything it mishandles is on the path every inference request takes. NVIDIA states that improper encoding or escaping of output could lead to information disclosure and data tampering. The CVSS vector is scored with a changed scope (S:C), meaning the impact lands outside the proxy's own security context; on a shared GPU node that is the direction that matters, since the proxy generally has access to more than the caller does. The record does not describe which output channel is mishandled or what an attacker can inject, so treat the concrete exploitation path as unknown.
Who can reach it
A local, low-privileged user on the host running OpenShell (CVSS AV:L/PR:L/UI:N). Authentication as some local principal is required; no user interaction is.
What to do
Install the fixed OpenShell for Linux release from NVIDIA advisory bundle 5872 and restart the inference proxy. The record does not name a fixed version - read the advisory for the version that applies to your install. No node drain or firmware work is involved.
References
Related entries
- Pure Storage FlashArray key rotation logging (Rapid Data Locking): The Key Encryption Key is written to logs duringCVE-2025-2327 · Pure Storage FlashArray key rotation logging (Rapid Data Locking)Medium
- TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer modelsCVE-2020-15211 · TensorFlow Lite (flatbuffer models)Medium
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`CVE-2026-65920 · diffusers (shard file loader)Medium
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryCVE-2026-71486 · vLLM OpenAI-compatible server (/v1/completions/derender and /v1/chat/completions/derender)Medium
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sCVE-2023-31306 · AMD graphics driver - dynamic power management (DPM) array index validationLow
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityCVE-2026-15605 · wandb SDK (`ArtifactManifestEntry.download`)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.