Executive brief
NVIDIA TensorRT, a high-performance deep learning inference library, contains a security vulnerability that could allow an attacker to modify data. This flaw could lead to data tampering, potentially affecting the integrity of AI model outputs or system operations. Organizations using TensorRT for machine learning applications should ensure they are running the latest patched versions to prevent unauthorized changes to their data.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in NVIDIA TensorRT. The flaw allows an attacker to write data past the end of an intended buffer, which can lead to data corruption or tampering. According to the CVSS vector, the attack can be executed over the network without authentication or user interaction. While the primary impact is on data integrity, there is also a potential for limited impact on system availability. Users are advised to refer to NVIDIA advisory 5836 for specific version information and remediation steps.
Affected products
- NVIDIA TensorRT
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record.