Impact
The vulnerability is a use-after-free condition in NVIDIA Triton Inference Server for Linux. If an object is freed, an attacker can trigger an access to that memory through subsequent operations, causing the server process to terminate. The official description states that a successful exploit might lead to denial of service to legitimate clients. No information about confidentiality or integrity impact is provided.
Affected Systems
All deployments of NVIDIA Triton Inference Server on Linux are potentially affected. The vendor has not disclosed specific affected versions, so any current installation may be vulnerable until a vendor-supplied fix is released.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the exploit can be triggered remotely by sending a crafted inference request; however, no public exploit has been reported. The risk is primarily to service availability rather than confidentiality or integrity.
OpenCVE Enrichment