Description
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Published: 2026-08-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Dynamo for Linux hosts a vulnerability in its multimodal serving topology that triggers an out‑of‑bounds write. An attacker capable of exploiting this flaw can execute arbitrary code, elevate privileges, tamper with data, cause denial of service, and gain confidential information. The weakness is identified as CWE‑288, reflecting a failure to properly authenticate or authorize actions that lead to this boundary violation.

Affected Systems

The affected product is NVIDIA Dynamo running on Linux. The specific versions are not enumerated in the advisory, so any installation of Dynamo that includes the multimodal serving topology component is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.8 categorizes this flaw as critical. No EPSS value is available, so the likelihood of exploitation cannot be quantified from the advisory. The vulnerability is not listed in the CISA KEV catalog, though the impact suggests a high risk to systems if the flaw is leveraged. Both local and remote exploitation scenarios are plausible: a remote attacker could target exposed Dynamo services, while a local attacker could trigger the OOB write via privileged processes; the exact vector is not detailed in the advisory.

Generated by OpenCVE AI on August 4, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check NVIDIA’s product‑security advisories for an official patch or update that remedies the out‑of‑bounds write in Dynamo’s multimodal serving topology and apply it immediately.
  • Restrict network access to Dynamo services by configuring firewalls or VPNs so that only trusted hosts can communicate with the multimodal serving component.
  • Enable host‑based security mechanisms such as SELinux or AppArmor to confine Dynamo processes and prevent them from escalating privileges through out‑of‑bounds writes.
  • Monitor system logs and application metrics for anomalous memory write patterns or unexpected privilege escalations, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dynamo
Vendors & Products Nvidia
Nvidia dynamo

Tue, 04 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in NVIDIA Dynamo Multimodal Serving

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-04T18:23:35.934Z

Reserved: 2026-01-21T19:09:48.283Z

Link: CVE-2026-24254

cve-icon Vulnrichment

Updated: 2026-08-04T18:23:31.291Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T18:16:49.937

Modified: 2026-08-07T19:34:45.060

Link: CVE-2026-24254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:38Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel