Impact
A vulnerability exists in NVIDIA Dynamo for Linux’s multimodal embedding cache. An attacker can submit two images that contain the same pixel byte sequence but have different dimensions, causing a hash collision in the cache. This correlation flaw may allow the attacker to silently replace or corrupt cached data, resulting in unauthorized data tampering. The weakness is a hash collision flaw (CWE‑1023).
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific affected versions are listed; all publicly available releases of the product are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5. EPSS data is not available, so the likelihood of exploitation is currently unknown. It is not listed in the CISA KEV catalog. The attack vector inferred from the description is remote, as images can be submitted over the network to the Dynamo service. Successful exploitation would enable an attacker to tamper with data processed by the cache, compromising data integrity at the application level.
OpenCVE Enrichment