Junglewise Threat Intelligence

CVE-2026-24180: NVIDIA DALI heap buffer overflow

CVE-2026-24180 · Severity: high · CVSS 7.3 · Published 2026-06-09

Technologies: Nvidia DALI. Vendors: Nvidia.

Executive brief

NVIDIA DALI, a library used to accelerate data loading and pre-processing for deep learning applications, contains a security vulnerability. An attacker with local access to a system could exploit this flaw to execute unauthorized code, tamper with data, or cause the application to crash. This could lead to a loss of data integrity or a disruption of critical AI research and production workflows.

Technical details

A heap-based buffer overflow (CWE-122) exists in NVIDIA DALI. The vulnerability is triggered when the library improperly handles memory allocation in a specific component, allowing an attacker to overwrite adjacent memory on the heap. Exploitation requires local access with low privileges and some level of user interaction (AV:L/PR:L/UI:R). If successfully exploited, an attacker can achieve arbitrary code execution, bypass security controls to view sensitive information, or cause a denial of service by crashing the affected process. Users are advised to refer to NVIDIA advisory 5814 for specific version patching information.

Affected products

  • NVIDIA DALI

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats