CVE-2026-24189
8.2NVIDIA · CUDA-Q
NVIDIA CUDA-Q contains an out-of-bounds read vulnerability in an endpoint, allowing unauthenticated attackers to trigger denial of service or information disclosure via maliciously crafted requests.
Executive summary
An unauthenticated out-of-bounds read vulnerability in NVIDIA CUDA-Q allows remote attackers to potentially cause a denial of service or disclose sensitive information.
Vulnerability
The vulnerability is an out-of-bounds read (CWE-125) occurring within an endpoint of the CUDA-Q software. An unauthenticated attacker can exploit this flaw by sending a specifically crafted request to the affected endpoint, which may lead to system instability or memory exposure.
Business impact
The potential for denial of service and information disclosure poses a significant risk to system availability and data confidentiality. With a CVSS score of 8.2, this vulnerability is classified as High severity, as it allows remote, unauthenticated actors to disrupt operations without requiring any prior system access or user interaction.
Remediation
Immediate Action: Update NVIDIA CUDA-Q to version 0.14.0 or later to remediate the underlying memory safety issue.
Proactive Monitoring: Monitor system logs for unusual request patterns directed at CUDA-Q endpoints and track service availability metrics for unexpected crashes.
Compensating Controls: Deploy a Web Application Firewall (WAF) or ingress filtering rules to inspect incoming requests for malformed payloads that deviate from expected communication protocols.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity rating and the potential for remote exploitation, organizations using NVIDIA CUDA-Q must prioritize patching to version 0.14.0. Immediate remediation is necessary to prevent potential service disruption and unauthorized information leakage resulting from this memory safety flaw.