作为新员工发现NVIDIA Triton中的内存损坏漏洞
blog.trailofbits.com | 博客 | #ai-security | #memory-corruption | #vulnerability-disclosure | #ai-infrastructure | #static-analysis | #nvidia-triton | #semgrep | #pwn2own
摘要
Trail of Bits 新入职工程师通过 Semgrep 静态分析与手动验证,在 NVIDIA Triton Inference Server 中发现两个可远程利用的内存损坏漏洞(CVE-2025-23310、CVE-2025-23311,CVSS 9.8),源于 HTTP 分块传输编码处理缺陷,已在 25.07 版本修复。
- 发布时间
- 收录时间
Skip to content