Impact
NVIDIA Apex for Linux contains an insecure deserialization vulnerability that can be triggered by untrusted data. The flaw permits an attacker to execute arbitrary code, causing potential denial of service, privilege escalation, data tampering, and information disclosure. The weakness aligns with CWE‑502, Insecure Deserialization.
Affected Systems
Vulnerable systems include any installation of NVIDIA Apex for Linux that runs PyTorch versions older than 2.6. The issue affects all users of Apex who have not upgraded their PyTorch dependency to 2.6 or newer.
Risk and Exploitability
The CVSS score of 9 indicates a high severity rating. Although an EPSS score is not available, the fact that it is not listed in the CISA Known Exploited Vulnerabilities catalog does not diminish its threat. Based on the description, the likely attack vector is remote, where an attacker can supply crafted data to trigger the deserialization path. Successful exploitation would give the attacker high-level access, making this vulnerability a high‑risk concern for any exposed Apex deployment.
OpenCVE Enrichment