CVE-2025-23335

NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Aug 2025, 16:41

Type Values Removed Values Added
Summary
  • (es) NVIDIA Triton Inference Server para Windows y Linux, así como el backend de Tensor RT, presentan una vulnerabilidad que permite a un atacante causar un subdesbordamiento mediante una configuración de modelo específica y una entrada específica. Una explotación exitosa de esta vulnerabilidad podría provocar una denegación de servicio.
First Time Nvidia
Linux
Nvidia triton Inference Server
Microsoft
Microsoft windows
Linux linux Kernel
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23335 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23335 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23335 - () https://www.cve.org/CVERecord?id=CVE-2025-23335 - Third Party Advisory
CPE cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

06 Aug 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 13:15

Updated : 2025-08-12 16:41


NVD link : CVE-2025-23335

Mitre link : CVE-2025-23335

CVE.ORG link : CVE-2025-23335


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

nvidia

  • triton_inference_server
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)