Deserialization of Untrusted Data in TensorRT-LLM - CVE-2026-24142
Published: May 19, 2026
TensorRT-LLM
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code, tamper with data, or disclose sensitive information.
The vulnerability exists due to unsafe deserialization in serialized handle processing when handling an unsafe serialized handle. A local user can provide a crafted serialized handle to execute arbitrary code, tamper with data, or disclose sensitive information.