ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

mediumAdvisoryimportance 25CVE-2026-24268
AI summary · glm-5.3-flash

ZDI disclosed a second TensorRT heap-based buffer overflow RCE (CVE-2026-24268, CVSS 7.8) in ONNX file parsing, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-593 covering another heap-based buffer overflow in NVIDIA TensorRT's ONNX file parsing. A remote attacker can execute arbitrary code if the target opens a malicious file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-24268.

  • Second TensorRT ONNX parsing flaw allows remote code execution.
  • User interaction via malicious file or page required.
  • CVSS 7.8; tracked as CVE-2026-24268.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-24268
NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow.

NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.

NVD description · AI analysis pending
7.8<1%
  • nvidia tensorrt
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.

This source does not provide full text. Read it at zerodayinitiative.com.