CyberRota Analysis
AI-GeneratedNVIDIA TensorRT-LLM for Linux is vulnerable due to a flaw in its restricted unpickler, allowing local, unauthenticated attackers to deserialize untrusted data. Exploiting this vulnerability could result in code execution, privilege escalation, data tampering, and information disclosure. Organizations utilizing TensorRT-LLM should prioritize patching to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.