NVIDIA Megatron-LM Code Injection Vulnerability Allowing Arbitrary Code Execution and Privilege Escalation
Vulnerability
A code injection vulnerability has been identified in NVIDIA Megatron-LM for all platforms. This issue arises in a script where an attacker can introduce malicious data, potentially leading to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.
Impact
Exploitation of this vulnerability allows for arbitrary code execution, unauthorized privilege escalation, and could lead to disclosure of sensitive information and unauthorized modification of data.
Remediation
Users are advised to update to version 0.14.0 or later. This update is available on the NVIDIA Megatron-LM GitHub releases page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
