Nvidia plugs security holes in AI software

Various AI software from Nvidia contains security vulnerabilities, some of which are highly risky. Updates close them.

listen Print view
Nvidia logo on graphics card

(Image: Konstantin Savusia/Shutterstock.com)

2 min. read

Developers have found security vulnerabilities in various AI software from Nvidia. Some of these pose a high risk. Updated software and repositories are available for those affected to secure the software.

The Nvidia projects Apex, Isaac-GR00T, Megatron LM, Merlin Transformers4Rec, NeMo Framework, and WebDataset are impacted. The vulnerability descriptions state that attackers can execute arbitrary code, extend their rights, spy on information, or manipulate data.

The company does not provide details on the individual vulnerabilities in the individual security bulletins but only discusses what malicious actors can do with them:

Videos by heise

In the individual security advisories, however, Nvidia refers to the respective Github repositories and the individual commits that plug the listed security leaks. IT managers should ensure that the updates are also applied to the software used to reduce the attack surface.

Vulnerabilities in AI software from Nvidia were most recently discovered in March. The HGX software “Hopper HGX for 8-GPU” contained two vulnerabilities that attackers could misuse to execute malicious code or paralyze the software (DoS).

(dmk)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.