Impact
NVIDIA Dynamo for Linux hosts a vulnerability in its multimodal serving topology that triggers an out‑of‑bounds write. An attacker capable of exploiting this flaw can execute arbitrary code, elevate privileges, tamper with data, cause denial of service, and gain confidential information. The weakness is identified as CWE‑288, reflecting a failure to properly authenticate or authorize actions that lead to this boundary violation.
Affected Systems
The affected product is NVIDIA Dynamo running on Linux. The specific versions are not enumerated in the advisory, so any installation of Dynamo that includes the multimodal serving topology component is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 categorizes this flaw as critical. No EPSS value is available, so the likelihood of exploitation cannot be quantified from the advisory. The vulnerability is not listed in the CISA KEV catalog, though the impact suggests a high risk to systems if the flaw is leveraged. Both local and remote exploitation scenarios are plausible: a remote attacker could target exposed Dynamo services, while a local attacker could trigger the OOB write via privileged processes; the exact vector is not detailed in the advisory.
OpenCVE Enrichment