Impact
The vulnerability is a write‑what‑where condition in NVIDIA TensorRT‑LLM (CWE‑123). An attacker who can trigger it could overwrite arbitrary memory locations, enabling data tampering, causing crashes that lead to denial of service, or leaking confidential information stored in memory.
Affected Systems
This flaw afflicts NVIDIA TensorRT‑LLM. Version information is not supplied, so all current releases may be at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, while the EPSS score of less than 1% suggests the vulnerability is unlikely to be widely exploited at present. The flaw is not listed in the CISA KEV catalog. Because the description does not specify a remote attack surface, the most likely attack vector is local or requires the attacker to supply malformed input to a TensorRT‑LLM‑enabled application. Successful exploitation would require the ability to trigger the write‑what‑where, potentially requiring privileges that permit execution of TensorRT‑LLM code.
OpenCVE Enrichment