Description
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Published: 2026-08-04
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA reports that the example and recipe code provided with its Dynamo package for Linux contains a flaw that can let an attacker trigger a system failure. If exploited, the vulnerability can allow arbitrary code execution, data modification, denial of service, or information disclosure, as summarized in the advisory. The weakness is identified as CWE‑1357, indicating a likely unhandled input or execution path that can lead to a crash or unintended behavior.

Affected Systems

The affected product is NVIDIA Dynamo for Linux. The flaw exists in the example and recipe bundles that ship with the installation. No specific product versions are listed, so all releases that include these bundled examples are potentially vulnerable until a patch is applied or the examples are removed or secured.

Risk and Exploitability

The CVSS score is 6.6, classifying the issue as medium severity. Because no EPSS score is provided, the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the attack vector is inferred to be local execution of malicious or modified example scripts; a remote attacker would need local file execution authority or a pre‑existing code execution capability. Despite the moderate score, the potential for system failure and data compromise requires prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest NVIDIA Dynamo update that contains the fix, as released by NVIDIA.
  • If an update is not yet available, remove or disable the example and recipe directories so no user can execute them unintentionally.
  • Limit permissions on the Dynamo installation and example directories to trusted users only and monitor for unexpected crashes or unauthorized code execution.
  • Configure SELinux or AppArmor to confine the Dynamo process and prevent it from executing arbitrary code or accessing sensitive files.

Generated by OpenCVE AI on August 4, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dynamo
Vendors & Products Nvidia
Nvidia dynamo

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Weaknesses CWE-1357
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-04T18:27:44.577Z

Reserved: 2026-05-19T19:55:51.495Z

Link: CVE-2026-47619

cve-icon Vulnrichment

Updated: 2026-08-04T18:27:40.299Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T18:16:51.490

Modified: 2026-08-07T17:12:38.430

Link: CVE-2026-47619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:24Z

Weaknesses
  • CWE-1357

    Reliance on Insufficiently Trustworthy Component