Deserialization of Untrusted Data in TensorRT-LLM - CVE-2026-24163
Published: May 19, 2026
TensorRT-LLM
Detailed vulnerability description
The vulnerability allows a local privileged user to execute arbitrary code, cause a denial of service, tamper with data, or disclose sensitive information.
The vulnerability exists due to unsafe deserialization in RPC testing when processing serialized data. A local privileged user can supply crafted serialized input to execute arbitrary code, cause a denial of service, tamper with data, or disclose sensitive information.