Executive brief
NVIDIA TRT-LLM, a library used for optimizing Large Language Model performance, contains a security flaw in its remote procedure call (RPC) testing component. An attacker with high-level access to the system could exploit this to run unauthorized commands, crash the service, or access sensitive data. This could lead to a full compromise of the affected machine and any data being processed by the AI models.
Technical details
An unsafe deserialization vulnerability (CWE-502) exists in the RPC testing component of NVIDIA TRT-LLM across all platforms. The flaw is triggered when the application processes untrusted data without sufficient validation, allowing an attacker to manipulate serialized objects. Exploitation requires local access with high privileges and involves high architectural complexity (AC:H). If successfully exploited, an attacker can achieve arbitrary code execution, cause a denial of service, or bypass security boundaries to access or modify sensitive information. Users should refer to NVIDIA advisory 5805 for specific patching instructions.
Affected products
- NVIDIA TRT-LLM All platforms
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record
- 2026-05-20: advisory: NVIDIA published security advisory 5805