Executive brief
NVIDIA Dynamo is a serving component used to deploy machine learning models on Linux systems. A vulnerability in its multimodal model serving topology allows an attacker to write data outside of allocated memory bounds, potentially leading to complete system compromise including unauthorized code execution, privilege escalation, data tampering, service disruption, and information theft.
Technical details
The vulnerability is a heap-based out-of-bounds write in NVIDIA Dynamo's multimodal serving topology component. The root cause involves improper bounds checking when processing multimodal model serving requests. An attacker with network access can trigger the out-of-bounds write without authentication or user interaction. Successful exploitation enables arbitrary code execution with the privileges of the Dynamo process, leading to complete system compromise including privilege escalation, data tampering, denial of service, and information disclosure. Patches are expected to be available through NVIDIA's security update process.
Affected products
- NVIDIA Dynamo for Linux <UNKNOWN>
Timeline
- 2026-08-04: disclosed