GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA TensorRT: An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with no

CVE-2026-24188NVIDIA / GPU stackcurated

Impact

An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with no privileges required. TensorRT sits inside almost every optimised inference deployment, so the affected surface is wide even where TensorRT is not the thing you deployed by name.

Who can reach it

Network, unauthenticated. Reached through whatever service embeds the TensorRT runtime and passes it externally-influenced input.

What to do

Update TensorRT per bulletin 5836 and rebuild every inference image that links it - including Triton images with the TensorRT backend. Cost: image rebuild plus rolling restart; inventory work is the expensive part because TensorRT is usually a transitive dependency.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.