PatchSiren cyber security CVE debrief
CVE-2026-24142 NVIDIA CVE debrief
CVE-2026-24142 is a medium-severity NVIDIA TensorRT-LLM vulnerability involving unsafe deserialization and an unsafe serialized handle. According to the supplied NVD record, a successful exploit may lead to code execution, data tampering, and information disclosure. The issue is scoped to TensorRT-LLM versions prior to 1.2 in the provided CPE criteria and is rated CVSS 6.3.
- Vendor
- NVIDIA
- Product
- TensorRT-LLM
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-24
Who should care
Teams running NVIDIA TensorRT-LLM, especially operators of shared model-serving environments and developers or integrators that process serialized TensorRT-LLM data. Organizations using versions before 1.2 should treat this as a real security maintenance item because the flaw can affect confidentiality, integrity, and availability.
Technical summary
The supplied record identifies CWE-502 (deserialization of untrusted data) and an unsafe serialized handle in NVIDIA TensorRT-LLM. NVD’s CVSS vector is AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L, indicating a local attack requiring low privileges and no user interaction, with scope change and low impact across confidentiality, integrity, and availability. The NVD CPE criteria mark nvidia:tensorrt_llm versions earlier than 1.2 as vulnerable.
Defensive priority
Medium. Prioritize remediation for any environment that allows lower-privileged users, plugins, jobs, or pipelines to reach TensorRT-LLM deserialization paths or serialized artifacts. Even though the CVSS score is moderate, the outcome can include code execution and data compromise.
Recommended defensive actions
- Upgrade NVIDIA TensorRT-LLM to a fixed release at or above version 1.2, if available from NVIDIA.
- Restrict access to any deserialization or serialized-handle ingestion paths to trusted, authenticated operators only.
- Avoid accepting serialized TensorRT-LLM artifacts from untrusted or partially trusted sources.
- Review deployment and job permissions so low-privilege local users cannot reach sensitive TensorRT-LLM processing paths.
- Monitor NVIDIA’s advisory and the official CVE/NVD records for any updated mitigation guidance or revised affected-version details.
Evidence notes
All claims in this debrief are drawn from the supplied official records: the CVE description, the NVD metadata, and the linked official references. The corpus identifies CWE-502, CVSS 6.3 with vector AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L, and vulnerable TensorRT-LLM CPE criteria ending before 1.2. No exploit steps or unverified mitigation details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24142 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24142
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24142 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24142
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/5805
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.