Impact
NVIDIA Dynamo for Linux contains a race condition that triggers during the singleton initialization of the LoRA manager. When properly exploited, the flaw can cause unauthorized modification of data held by Dynamo and can bring the application to a halt, resulting in a denial of service. The weakness is identified as a concurrency flaw, which the description labels as a race condition.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific versions are listed in the advisory, so any deployment of Dynamo at the time of the vulnerability could potentially be impacted. Users should verify their installed version against the vendor’s security page.
Risk and Exploitability
The vulnerability is scored with a CVSS of 6.5, indicating a moderate severity. Exploit probability data (EPSS) is not available, and the issue is not listed in the CISA KEV catalog. While the description does not explicitly state the attack surface, it is inferred that the race condition requires concurrent access during application startup or re‑initialization, implying a local or privileged attacker could trigger the exploit by manipulating process scheduling or initiating multiple instances. The lack of a public exploit reduces the likelihood of immediate widespread attacks, but the fault potentially allows an attacker with sufficient access to alter application data or force a service outage.
OpenCVE Enrichment