Database/AI/ML frameworks & serving
NVIDIA TensorRT: out-of-bounds read while processing a model causes denial of service
Impact
A malformed input processed by TensorRT reads past the end of a buffer and the process dies. On a GPU node this takes down the inference process holding the device, and in a shared serving tier any tenant able to get a model or engine file loaded can crash the server repeatedly. NVIDIA scores availability impact only - no confidentiality or integrity loss - and the vector requires local access plus user interaction, so this is a build/convert-time or model-load-time crash rather than a remote network kill. There is no code execution claim in the advisory.
Who can reach it
Local access to the machine running TensorRT, with user interaction required (someone has to load or convert the attacker-supplied artifact). No authentication to a network service is involved.
What to do
Apply the TensorRT update referenced in NVIDIA bulletin 2026/5891 and restart the affected inference or conversion processes. No node drain or firmware work is implied; the advisory text in the record does not name a fixed version, so check the bulletin for the version that applies to your branch.
References
Related entries
- NVIDIA TensorRT: An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with noCVE-2026-24188 · NVIDIA TensorRTHigh
- Kubeflow (Pipelines UI): Stored XSS in the pipeline viewCVE-2024-9526 · Kubeflow (Pipelines UI)Medium
- JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRFCVE-2026-102904 · JupyterLab PyPI Extension Manager (uninstall handler argument injection)Medium
- Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalationCVE-2026-24693 · Intel oneCCL Bindings for PyTorch (protection mechanism failure)Medium
- TorchServe (model/workflow API): Information disclosure of files on the serving hostCVE-2023-48299 · TorchServe (model/workflow API)Medium
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.