NVIDIA Triton Inference Server Out-of-Bounds Write Vulnerability in Python Backend Allowing Remote Code Execution
Vulnerability
A vulnerability exists in NVIDIA Triton Inference Server for Windows and Linux, specifically within the Python backend. This vulnerability allows an attacker to cause an out-of-bounds write by sending a crafted request. Exploitation of this issue could lead to remote code execution, denial of service, data tampering, or information disclosure.
Impact
Successful exploitation could result in remote code execution, denial of service, data tampering, or unauthorized information disclosure.
Remediation
Users are advised to update to version 25.07 or later. The latest release can be downloaded from the Triton Inference Server Releases page on GitHub.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
