Critical Remote Code Execution in NVIDIA TensorRT (CVE‑2026‑24238) via ONNX Parsing Flaw
What It Is — NVIDIA TensorRT’s ONNX model parser fails to validate array indexes in Slice operations, allowing a write‑past‑the‑end condition that can be leveraged for remote code execution. The flaw is tracked as CVE‑2026‑24238.
Exploitability — CVSS 7.8 (High). Exploitation requires user interaction (visiting a malicious page or opening a crafted file), but a successful attack runs arbitrary code in the host process. No public exploit is known yet; a vendor patch is available.
Affected Products — NVIDIA TensorRT (all versions prior to the August 2026 security update).
Why It Matters for Compliance & Audit Readiness —
- Demonstrates the need for continuous vulnerability management to satisfy SOC 2 Security criteria (CC6.1 – System Operations).
- Unpatched code‑execution paths constitute a control gap; mapping them to your control framework provides audit‑ready evidence.
- Ongoing patch verification can be captured in a Trust Center dashboard to prove due diligence to customers and regulators.
Recommended Actions —
- Deploy NVIDIA’s September 2026 patch immediately on all TensorRT instances.
- Update your asset inventory to tag TensorRT versions and enable automated compliance scanning.
- Map the vulnerability to SOC 2 CC6.1 and record remediation evidence in your continuous‑compliance platform.
- Incorporate runtime integrity checks for ONNX model parsing into your secure‑development lifecycle.