← Back to search

CVE-2026-24254

9.8 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-07

AI risk analysis

Summary
The vulnerability in NVIDIA Dynamo for Linux allows an attacker to perform an out-of-bounds write, potentially leading to code execution and data tampering.
Exploitability
Exploitation requires access to the affected system and knowledge of the specific vulnerability, making it moderately difficult.
Blast radius
If exploited, the vulnerability could result in code execution, privilege escalation, and data loss, impacting the system's availability and integrity.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 2.590 or later.
rcedata-tamperingprivilege-escalationout-of-bounds-write

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-288

Vendors

nvidia, linux

Products

dynamo, linux kernel

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.