Executive brief
NVIDIA TensorRT, a high-performance deep learning inference library, is affected by a memory handling vulnerability. An attacker could exploit this flaw to execute unauthorized code on a target system. This could lead to a complete compromise of the system's confidentiality, integrity, and availability, potentially impacting AI model processing and sensitive data.
Technical details
NVIDIA TensorRT is vulnerable to a heap-based buffer overflow (CWE-122). The vulnerability exists in versions up to v10.16.1. An attacker can exploit this by providing specially crafted input that triggers an overflow in the heap memory region. While the attack vector is local, it requires no special privileges, though it does necessitate user interaction (UI:R). Successful exploitation can lead to arbitrary code execution with the privileges of the application using the TensorRT library. NVIDIA has released information regarding this vulnerability in advisory A_ID 5855.
Affected products
- NVIDIA TensorRT v0 - v10.16.1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory