Impact
NVIDIA Triton Inference Server for Linux contains a flaw where it fails to handle data that is heavily compressed. When an attacker sends such data to the server, the internal handling logic can result in the. The weakness is identified as CWE-409, reflecting improper resource allocation.
Affected Systems
The vulnerability affects all installations of NVIDIA Triton on Linux until the vendor releases a patch. No specific version range is supplied in the advisory, so any deployed instance is potentially impacted until it is updated.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EP%, suggesting that exploitation is unlikely but not impossible. This vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is remote, with an attacker able to send specially crafted, highly compressed input to the inference endpoint over the network. Successful exploitation would likely cause the Triton service to halt or become unusably slow for all users on that instance.
OpenCVE Enrichment