NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nvidia:megatron-lm:*:*:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:-:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:rc0:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:rc1:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:rc2:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:rc3:*:*:*:*:*:* cpe:2.3:a:nvidia:megatron-lm:0.13.0:rc4:*:*:*:*:*:* |
Thu, 25 Sep 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia megatron-lm |
|
| Vendors & Products |
Nvidia
Nvidia megatron-lm |
Wed, 24 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Sep 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published: 2025-09-24T13:13:43.423Z
Updated: 2025-09-24T13:57:24.554Z
Reserved: 2025-01-14T01:07:21.737Z
Link: CVE-2025-23348
Updated: 2025-09-24T13:57:18.947Z
Status : Analyzed
Published: 2025-09-24T14:15:48.663
Modified: 2025-10-10T18:24:13.447
Link: CVE-2025-23348
No data.