← Back to search

CVE-2026-24254

9.8 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-07

AI risk analysis

Summary
The vulnerability in NVIDIA Dynamo for Linux allows an attacker to perform out-of-bounds writes, potentially leading to code execution and data tampering.
Exploitability
Exploitation requires access to the affected system; no specific preconditions other than system access are known.
Blast radius
If exploited, this vulnerability could result in significant damage including code execution and data compromise across multiple systems.
Prioritized remediation
Apply vendor patches for NVIDIA Dynamo immediately to mitigate the risk of exploitation.
rcedata-tamperingcode-executionpatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-288

Vendors

nvidia, linux

Products

dynamo, linux kernel

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.