CVE-2026-24213

8.0

NVIDIA · Triton Inference Server

NVIDIA Triton Inference Server is susceptible to an out-of-bounds read vulnerability in the DALI backend, which may allow an authenticated attacker to access sensitive memory or crash the service.

Executive summary

An out-of-bounds read vulnerability in the NVIDIA Triton Inference Server DALI backend poses a significant risk to data confidentiality and service stability.

Vulnerability

This is an out-of-bounds read vulnerability in the DALI backend triggered during processing, requiring low-privileged authentication and user interaction to potentially expose sensitive memory contents (AV:N/AC:L/PR:L/UI:R).

Business impact

Exploitation of this vulnerability could lead to the exposure of sensitive inference data or the complete crash of the inference server. Given the 8.0 CVSS score, this represents a critical risk to the reliability of AI services and the protection of proprietary data processed within the inference environment.

Remediation

Immediate Action: Upgrade to NVIDIA Triton Inference Server version r26.03 or later to patch the vulnerable memory handling logic in the DALI backend.

Proactive Monitoring: Review access logs for unusual request patterns and monitor system health metrics for memory-related errors or unexpected service crashes.

Compensating Controls: Restrict access to the inference server to trusted users only and enforce the principle of least privilege to minimize the potential for an authenticated attacker to reach the vulnerable code path.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Administrators must schedule an update to version r26.03 as soon as possible. Following the update, verify the integrity of the inference models and confirm that the DALI backend is operating correctly within the updated environment.

More NVIDIA CVEs