Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Heap‑Based Buffer Overflow in NVIDIA TensorRT ONNX Parsing Enables Remote Code Execution (CVE‑2026‑24272)

A heap‑based buffer overflow in NVIDIA TensorRT's ONNX parser (CVE‑2026‑24272) allows remote code execution when a user opens a malicious model file. The flaw underscores the need for robust control mapping and continuous evidence collection to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
zerodayinitiative.com

Heap‑Based Buffer Overflow in NVIDIA TensorRT ONNX Parsing Enables Remote Code Execution (CVE‑2026‑24272)

What It Is – A heap‑based buffer overflow resides in the ONNX model parser of NVIDIA TensorRT. An attacker who convinces a user to open a malicious ONNX file (or visit a page that loads one) can overwrite memory and execute arbitrary code in the context of the TensorRT process.

Exploitability – CVSS 7.8 (High). The vulnerability is locally exploitable with required user interaction (malicious file/page). No public exploits have been observed, but the low attack complexity and high impact make it a prime target for opportunistic actors.

Affected Products – NVIDIA TensorRT (all versions prior to the August 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The flaw highlights a gap in secure‑development and code‑validation controls (SOC 2 CC6.1 System Operations, CC7.1 Change Management). Mapping this to your control framework demonstrates due diligence.
  • Continuous Evidence – Applying NVIDIA’s patch and capturing patch‑deployment logs provides immutable audit evidence of risk mitigation, a key requirement for SOC 2 readiness.
  • Enterprise Buyer Expectations – Prospective customers increasingly request proof that critical AI/ML components are patched and monitored; a documented remediation workflow satisfies that demand.

Recommended Actions

  • Inventory all servers and containers running TensorRT; flag any that lack the August 2026 patch.
  • Deploy NVIDIA’s security update immediately and verify version compliance via automated tooling.
  • Map the vulnerability to SOC 2 controls (CC6.1, CC7.1) in your compliance matrix; record remediation steps as evidence.
  • Integrate continuous monitoring (e.g., SBOM checks, vulnerability scanners) to detect future library‑level flaws.

Source: Zero Day Initiative advisory ZDI‑26‑591

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-591/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →