Impact
NVIDIA TensorRT contains a heap-based buffer overflow that can be triggered by malicious input. The overflow can overwrite adjacent memory and may give an attacker control of the execution flow, resulting in arbitrary code execution. The weakness is identified as CWE-122, a classic heap corruption flaw.
Affected Systems
The affected product is NVIDIA TensorRT. No specific version numbers are provided in the advisory, so all installations of TensorRT are potentially vulnerable until the issue is mitigated.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of less than 1% shows that the likelihood of an exploit appearing in the wild is currently low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector would involve an attacker delivering crafted model data or input into TensorRT, which can then trigger the overflow and lead to code execution. Even with the low exploitation probability, the impact of successful exploitation is significant because it can compromise the entire host running TensorRT.
OpenCVE Enrichment