Impact
NVIDIA Triton Inference Server for Linux contains a use‑after‑free bug that can cause the server process to crash when an attacker accesses freed memory. A malicious inference request can trigger the crash, leading to a denial of service for legitimate clients. The vulnerability does not affect confidentiality or integrity, only availability.
Affected Systems
All deployments of NVIDIA Triton Inference Server running on Linux are potentially affected. The vendor has not identified specific versions, so any currently installed release may be vulnerable until a vendor‑supplied fix is released.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker could plausibly trigger the crash remotely by sending a crafted request to the inference endpoint; no public exploit has been reported.
OpenCVE Enrichment