8.4
CVE-2026-24233
- EPSS 0.26%
- Veröffentlicht 14.07.2026 20:00:37
- Zuletzt bearbeitet 15.07.2026 18:20:21
- CVE-Watchlists
- Unerledigt
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNVIDIA
≫
Produkt
TensorRT-LLM
Default Statusunaffected
Version <=
v1.3.0 rc14
Version
0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.178 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Nvidia | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://nvd.nist.gov/vuln/detail/CVE-2026-24233
https://www.cve.org/CVERecord?id=CVE-2026-24233