Executive brief
NVIDIA DALI, a library used to accelerate data loading and pre-processing for deep learning applications, contains a security vulnerability. An attacker with local access to a system could exploit this flaw to gain unauthorized control, modify sensitive data, or cause the application to crash. This could lead to a full system compromise or disruption of critical AI training and inference workflows.
Technical details
A vulnerability exists in NVIDIA DALI due to improper validation of an array index (CWE-129). An attacker with local access and low privileges can exploit this flaw, though it requires some level of user interaction. Successful exploitation allows for out-of-bounds memory access, which can be leveraged to achieve arbitrary code execution, bypass security protections to disclose information, or cause a denial of service through application crashes. The vulnerability is tracked as CVE-2026-24181 and has been assigned a CVSS v3.1 base score of 7.3.
Affected products
- NVIDIA DALI
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory