CVE-2024-0116
Triton Inference Server vulnerability analysis and mitigation

Overview

NVIDIA Triton Inference Server has been identified with vulnerability CVE-2024-0116, discovered and disclosed in September 2024. This vulnerability affects versions v19.11 through v24.08 of the Triton Inference Server running on Linux platforms. The issue involves an out-of-bounds read vulnerability that can occur when a shared memory region is released while still in use (NVIDIA Security).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 4.9 (Medium severity) with the vector string AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The technical nature of the vulnerability is classified as CWE-125 (Out-of-bounds Read), which occurs when a user releases a shared memory region while it is still being accessed (NVIDIA Security, Red Hat CVE).

Impact

A successful exploitation of this vulnerability can lead to denial of service (DoS) in the affected system. The vulnerability specifically impacts the availability of the service while not affecting confidentiality or integrity aspects (NVIDIA Security).

Mitigation and workarounds

NVIDIA has released version 24.09 of the Triton Inference Server to address this vulnerability. Users are advised to upgrade to this version. Additionally, users deploying the server in production settings should follow the Secure Deployment Considerations Guide and ensure that logging and shared memory APIs are protected for use by authorized users only (NVIDIA Security).

Community reactions

The vulnerability was responsibly disclosed by security researcher r3pwnx, demonstrating ongoing security research and responsible disclosure practices in the field (NVIDIA Security).

Additional resources


SourceThis report was generated using AI

Related Triton Inference Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33211HIGH7.5
  • Triton Inference ServerTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoYesDec 03, 2025
CVE-2025-33201HIGH7.5
  • Triton Inference ServerTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoYesDec 03, 2025
CVE-2025-23336HIGH7.5
  • Triton Inference ServerTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoYesSep 17, 2025
CVE-2025-23329HIGH7.5
  • Triton Inference ServerTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoYesSep 17, 2025
CVE-2025-33202MEDIUM6.5
  • Triton Inference ServerTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoYesNov 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management