Junglewise Threat Intelligence

CVE-2026-47473: NVIDIA TensorRT-LLM write-what-where condition

CVE-2026-47473 · Severity: high · CVSS 7.4 · Published 2026-07-14

Technologies: Nvidia TensorRT-LLM. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT-LLM, a library used to optimize the performance of large language models, contains a security vulnerability. An attacker with local access to the system could potentially modify sensitive data, cause the software to crash, or gain unauthorized access to information. This could disrupt AI-driven services or lead to the corruption of critical business data processed by the model.

Technical details

NVIDIA TensorRT-LLM is affected by a write-what-where condition (CWE-123). The vulnerability allows a local attacker to write arbitrary data to an arbitrary memory location. While the attack complexity is rated as high, a successful exploit could lead to a complete compromise of confidentiality, integrity, and availability (C/I/A). The issue is present in versions up to and including v1.3.0 rc16. Security engineers should monitor for updates from NVIDIA to remediate this memory corruption flaw.

Affected products

  • NVIDIA TensorRT-LLM v1.3.0 rc16 and earlier

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-47473 by NVIDIA.

References

Related threats