Junglewise Threat Intelligence

CVE-2026-24156: NVIDIA DALI deserialization of untrusted data

CVE-2026-24156 · Severity: high · CVSS 7.3 · Published 2026-04-07

Technologies: Nvidia DALI. Vendors: Nvidia.

Executive brief

NVIDIA DALI, a library used to accelerate data loading for deep learning applications, contains a security flaw in how it processes data. An attacker could use this vulnerability to execute unauthorized commands on a system where the library is installed. This could lead to a complete compromise of the affected machine, potentially exposing sensitive AI models or training data.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in NVIDIA DALI versions prior to 2.0.0. The flaw allows a local attacker with low privileges to execute arbitrary code by tricking a user into processing a specially crafted file. The attack vector is local (AV:L) and requires user interaction (UI:R). Successful exploitation results in high impact to confidentiality, integrity, and availability. The issue is addressed in NVIDIA DALI version 2.0.0.

Affected products

  • NVIDIA DALI (Data Loading Library) All versions prior to 2.0.0

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory

References

Related threats