CVE-2025-23319

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Aug 2025, 16:34

Type Values Removed Values Added
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23319 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23319 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23319 - () https://www.cve.org/CVERecord?id=CVE-2025-23319 - Third Party Advisory
First Time Microsoft
Nvidia
Nvidia triton Inference Server
Linux
Microsoft windows
Linux linux Kernel
Summary
  • (es) NVIDIA Triton Inference Server para Windows y Linux contiene una vulnerabilidad en el backend de Python, donde un atacante podría provocar una escritura fuera de los límites al enviar una solicitud. Una explotación exitosa de esta vulnerabilidad podría provocar ejecución remota de código, denegación de servicio, manipulación de datos o divulgación de información.
CPE cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
CWE CWE-787

06 Aug 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 13:15

Updated : 2025-08-12 16:34


NVD link : CVE-2025-23319

Mitre link : CVE-2025-23319

CVE.ORG link : CVE-2025-23319


JSON object : View

Products Affected

linux

  • linux_kernel

nvidia

  • triton_inference_server

microsoft

  • windows
CWE
CWE-805

Buffer Access with Incorrect Length Value

CWE-787

Out-of-bounds Write