Junglewise Threat Intelligence

CVE-2026-24238: NVIDIA TensorRT improper validation of array index

CVE-2026-24238 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Nvidia TensorRT. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT, a software library used to optimize high-performance deep learning inference, contains a security flaw. An attacker could exploit this vulnerability by tricking a user into interacting with a malicious file or application, potentially allowing the attacker to run unauthorized code on the system. This could lead to a complete compromise of the affected machine, including data theft or system disruption.

Technical details

A vulnerability exists in NVIDIA TensorRT (up to version 10.16.1) due to improper validation of an array index (CWE-129). The flaw is triggered when the library processes specially crafted input, leading to an out-of-bounds access. This is a local attack vector that requires user interaction (UI:R), such as opening a malicious model file. If successfully exploited, an attacker can achieve arbitrary code execution with the privileges of the application using the TensorRT library, potentially leading to full system compromise.

Affected products

  • NVIDIA TensorRT v0 - v10.16.1

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats