Executive brief
NVIDIA DALI, a library used to accelerate data loading and pre-processing for deep learning applications, contains a security vulnerability. An attacker with local access to a system could exploit this flaw to execute unauthorized code, tamper with data, or cause the application to crash. This could lead to a loss of data integrity or a disruption of critical AI research and production workflows.
Technical details
A heap-based buffer overflow (CWE-122) exists in NVIDIA DALI. The vulnerability is triggered when the library improperly handles memory allocation in a specific component, allowing an attacker to overwrite adjacent memory on the heap. Exploitation requires local access with low privileges and some level of user interaction (AV:L/PR:L/UI:R). If successfully exploited, an attacker can achieve arbitrary code execution, bypass security controls to view sensitive information, or cause a denial of service by crashing the affected process. Users are advised to refer to NVIDIA advisory 5814 for specific version patching information.
Affected products
- NVIDIA DALI
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory