Impact
NVIDIA Triton Inference Server on Linux has a defect where it does not correctly process highly compressed data that arrives in inference requests. Sending such data can disrupt the service by causing it to become unresponsive or crash, leading to a denial of service for all clients. The weakness is identified as CWE-409, indicating improper resource management.
Affected Systems
The flaw affects all deployed instances of NVIDIA Triton Inference Server running on Linux. No specific version range is indicated, so every current installation is potentially impacted until the vendor releases a patch.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity. The EPSS score of less than 1% indicates that the probability of a successful exploit in the wild is low, though not impossible. This vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote delivery of highly compressed data over the network to the inference endpoint, which would trigger the improper handling and result in a service disruption.
OpenCVE Enrichment