Executive brief
NVIDIA Dynamo is a machine learning optimization tool for Linux systems. This vulnerability allows an attacker to trigger a race condition during initialization of the LoRA (Low-Rank Adaptation) manager component, potentially leading to corrupted data and service disruptions in systems relying on Dynamo for AI model inference or training.
Technical details
A race condition exists in the LoRA manager singleton initialization code in NVIDIA Dynamo for Linux. The vulnerability allows an attacker to exploit timing gaps during concurrent initialization attempts, potentially causing data tampering and denial of service. The attack is likely triggered through local or network access to the Dynamo service without requiring elevated privileges, though the exact attack vector depends on the deployment context. Successful exploitation can result in corrupted model state or process crashes, affecting availability and data integrity of machine learning workloads.
Affected products
- NVIDIA Dynamo <UNKNOWN>
Timeline
- 2026-08-04: disclosed