CVE-2026-24254Patch(linux / dynamo)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux dynamo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamo
  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
dynamolinux_kernel

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-05: 2Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-05: 2Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 108-0508-06
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-052
Patch2
2026-08-061
General1
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    NVIDIA warns of a critical 9.8 CVSS NVIDIA Dynamo flaw (CVE-2026-24254) leading to code execution. Update to the latest version to secure your systems. #NVIDIADynamo #Vulnerability #CyberSecurity #CodeExecution #CVE202624254 http://securityonline.info/nvidia-dynamo-code-execution-flaw/

    Post summary

    NVIDIA warns of a critical code execution flaw (CVE‑2026‑24254) with a CVSS score of 9.8 and urges users to update to the latest version.

    00120475
    12.9K followersView on X
  • Sami Laiho@samilaiho
    Patch

    Several vulnerability in NVIDIA Dynamo for Linux URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24254 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    The NVD entry identifies CVE-2026-24254 as a critical vulnerability with an official fix available, but provides no evidence of exploitation or PoC.

    00001956
    30.6K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    General

    CVE-2026-24254 NVIDIA Dynamo Unauthenticated RCE in AI inference orchestration could allow crafted network requests to compromise multimodal serving infrastructure Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-04/TIER_2_CVE-2026-24254.md #CyberSecurity #AISecurity #VulnerabilityManagement

    Post summary

    The notice references CVE-2026-24254, an unauthenticated RCE in NVIDIA Dynamo’s AI inference orchestration, and points to a detailed analysis report for further information.

    0000059
    59 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
Appnvidiadynamo---

Explore more