← Back to search

CVE-2026-24255

7.5 HIGHpublic exploit available

Published 2026-08-04 · Updated 2026-08-07

AI risk analysis

Summary
The vulnerability allows an attacker to cause a hash collision by submitting images with identical pixel byte sequences but different dimensions, potentially leading to data tampering.
Exploitability
Exploitation requires crafting specific image inputs and access to the affected NVIDIA Dynamo for Linux system; public exploits are available.
Blast radius
If exploited, this could result in unauthorized data manipulation on vulnerable systems, impacting data integrity.
Prioritized remediation
Apply vendor patches or upgrade to a version of NVIDIA Dynamo for Linux that addresses this vulnerability.
data-tamperingimage-processingnvidia

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-1023

Vendors

nvidia, linux

Products

dynamo, linux kernel

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.