Impact
The vulnerability is a heap-based buffer overflow that can allow an attacker to execute arbitrary code in the context of the TensorRT process. This flaw can arise when malicious data is fed into TensorRT components, potentially leading to a loss of confidentiality, integrity, and availability. The flaw is classified as CWE-122 and is assigned a CVSS score of 7.8, though specific version ranges have not been published. The vendor has not released a formal fix or workaround in the publicly available documentation, so administrators should treat all deployments with caution until a patch is issued.
Affected Systems
NVIDIA TensorRT. All versions are potentially affected; no specific version range was published by NVIDIA. Affected systems may include any platform using TensorRT for inference or deployment of deep learning models.
Risk and Exploitability
The EPSS score is below 1%, suggesting that exploitation of this weakness is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply crafted data to a TensorRT component; therefore the vector is likely local or requires compromise of an application that uses TensorRT. The severity combined with the low exploitation probability still warrants monitoring and preparation for a patch.
OpenCVE Enrichment