GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA TensorRT: out-of-bounds read while processing a model causes denial of service

CVSS 5.5CVE-2026-65122AI/ML frameworks & servingcurated

Impact

A malformed input processed by TensorRT reads past the end of a buffer and the process dies. On a GPU node this takes down the inference process holding the device, and in a shared serving tier any tenant able to get a model or engine file loaded can crash the server repeatedly. NVIDIA scores availability impact only - no confidentiality or integrity loss - and the vector requires local access plus user interaction, so this is a build/convert-time or model-load-time crash rather than a remote network kill. There is no code execution claim in the advisory.

Who can reach it

Local access to the machine running TensorRT, with user interaction required (someone has to load or convert the attacker-supplied artifact). No authentication to a network service is involved.

What to do

Apply the TensorRT update referenced in NVIDIA bulletin 2026/5891 and restart the affected inference or conversion processes. No node drain or firmware work is implied; the advisory text in the record does not name a fixed version, so check the bulletin for the version that applies to your branch.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.