Home » Database

AVID-2026-R1349

Description

Vulnerability CVE-2024-0116

Details

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is in use. A successful exploit of this vulnerability may lead to denial of service.

Reason for inclusion in AVID: CVE-2024-0116 describes a software vulnerability in NVIDIA Triton Inference Server (AI serving stack) that allows an out-of-bounds read leading to denial of service. This affects a component used to build/run general-purpose AI systems, is a software supply-chain-relevant issue, and is a clearly defined security vulnerability (CWE-125) with CVSS impact. The report provides sufficient signals (description, CVSS, CWE, references) for classification.

References

Affected or Relevant Artifacts

  • Developer: NVIDIA
  • Deployer: NVIDIA
  • Artifact Details:
TypeName
SystemTriton Inference Server

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score4.9
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🔴 High
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🔴 High

CWE

IDDescription
CWE-125CWE-125 Out-of-bounds Read

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-10-01
  • Version: 0.3.3
  • AVID Entry