Triton Inference Server: RCE / privesc / data tampering via model-load path traversal (`--model-control explicit`)
CVE-2023-31036NVIDIA / GPU stackcurated
Impact
RCE / privesc / data tampering via model-load path traversal (--model-control explicit)
Who can reach it
Authenticated user of the inference endpoint; malicious model repo
What to do
Upgrade Triton to 2.40+; rebuild inference serving images; disable explicit model control on multi-tenant endpoints
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.