CVE-2026-24254
NVIDIA · Dynamo
NVIDIA Dynamo for Linux is vulnerable to an out-of-bounds write in the multimodal serving topology, potentially leading to remote code execution or system compromise.
Executive summary
A critical out-of-bounds write vulnerability in NVIDIA Dynamo allows unauthenticated remote attackers to execute arbitrary code and compromise system integrity.
Vulnerability
The flaw exists within the multimodal serving topology, where improper input handling enables an out-of-bounds write. This vulnerability is remotely exploitable without authentication, as indicated by the CVSS attack vector (AV:N/PR:N).
Business impact
The potential for remote code execution poses a severe threat to business operations, as it allows attackers to gain unauthorized control over affected systems. With a CVSS score of 9.8, this vulnerability carries a high risk of data exfiltration, service disruption, and complete system compromise, necessitating immediate attention.
Remediation
Immediate Action: Update NVIDIA Dynamo to version 1.1.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Inspect network and application logs for unusual traffic patterns or unexpected process execution originating from the Dynamo service.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter and block malicious payloads targeting the multimodal serving interface until patching is complete.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity score and the potential for total system compromise, organizations should prioritize patching NVIDIA Dynamo immediately. Ensure that the update is applied across all instances to eliminate the risk of remote exploitation.