Sceawere

Vulnerability Detail

CVE-2026-65102UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NVIDIA DeepStream Integer Overflow Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
10h ago
Vendor
NVIDIA
Product
DeepStream
Attack Type
CWE-190 Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful exploit of this vulnerability might lead to denial of service, information disclosure, data tampering.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-29T15:17:27.453Z",
  "pubdate": "2026-09-29T15:17:27.453Z",
  "executiveSummary": "NVIDIA DeepStream contains a critical integer overflow vulnerability stemming from improper validation of tensor dimensions within YAML configuration files. This flaw allows a remote or local attacker to manipulate memory allocation parameters, potentially leading to heap-based buffer overflows or memory corruption. The vulnerability poses significant security risks, including Denial of Service (DoS) through application crashes, unauthorized information disclosure from process memory, and potential data tampering. Successful exploitation requires an attacker to possess the ability to supply or modify a crafted configuration file that the DeepStream application processes. The impact is severe as it undermines the integrity and availability of the AI inference pipeline, potentially allowing for remote code execution depending on the subsequent memory corruption pattern. Organizations utilizing DeepStream are advised to treat configuration files as untrusted input to mitigate the risk of exploitation.",
  "technicalDetails": "The root cause of this vulnerability lies in an integer overflow condition triggered during the parsing and initialization phase of NVIDIA DeepStream's tensor management component. When the application processes a YAML configuration file, it reads user-defined tensor dimensions to allocate necessary buffers for data processing. If these dimension values are crafted to be excessively large, the arithmetic operations involved in calculating the total buffer size (such as multiplication of width, height, and depth) can exceed the maximum value representable by the integer type utilized in the calculation.\nSpecifically, the overflow leads to the allocation of a memory buffer significantly smaller than what is required for the intended data structure. Once the application proceeds to copy input tensor data into this undersized buffer, a heap-based buffer overflow occurs. This memory corruption overwrites adjacent data structures or metadata in the heap, leading to non-deterministic behavior.\nThe attack flow commences with the attacker providing a malicious YAML configuration file to the DeepStream runtime. Upon loading the configuration, the parser reads the manipulated tensor dimensions and performs the vulnerable integer arithmetic. Because the resulting size calculation wraps around due to the overflow, the memory allocator reserves an insufficient amount of heap space. During the subsequent inference execution, the application attempts to write high-dimensional data into this constrained memory block. Depending on the memory layout and the nature of the overwritten data, the impact ranges from a segmentation fault (Denial of Service) to the overwriting of function pointers or object headers, which can facilitate arbitrary code execution.\nThe vulnerability does not strictly require network exposure, as it can be exploited in any context where an attacker can supply a malicious configuration file to the pipeline, including local deployments or containerized environments. There is no requirement for specific authentication or elevated privileges if the application automatically parses configuration files provided by an external source or user-controllable path. Post-exploitation, an attacker can leverage the memory corruption to exfiltrate sensitive inference data residing in adjacent memory segments or gain control over the instruction pointer to execute malicious payloads within the context of the DeepStream process."
}
CVE-2026-65102: NVIDIA DeepStream Integer Overflow Vulnerability (HIGH Severity, CVSS: 7.8) | Sceawere