HomeSecurityCritical flaw in Nvidia's NeMo Gen-AI framework

Critical flaw in Nvidia's NeMo Gen-AI framework

Artificial intelligence tech giant Nvidia has highlighted a major security flaw in its NeMo AI creation framework, warning that malicious hackers could execute code and compromise data on systems using the platform.

See also: Critical flaw in NVIDIA Container Toolkit allows complete computer takeover

Nvidia NeMo

“Nvidia NeMo contains a vulnerability in SaveRestoreConnector where a user can cause a path traversal issue via an insecure .tar file extraction. A successful exploitation of this vulnerability could lead to code execution and data tampering,” the company said in a statement.

Data tampering refers to the intentional alteration of data to deceive or mislead. This malicious activity poses a significant threat to the integrity, confidentiality, and availability of information in any system. Hackers can use a variety of means to alter data, such as modifying files, inserting false information, or deleting critical data altogether. The consequences of a data breach can be severe, affecting everything from business operations to the privacy and security of personal data. Organizations must implement strong cybersecurity measures, such as encryption and regular data audits, to proactively detect and prevent breach attempts.

Nvidia has flagged the flaw in the NeMo framework as CVE-2024-0129 with a CVSS severity rating of 6.3/10. The issue affects the framework on Windows, Linux, and macOS.

See also: Nvidia: Shares fall in the US market

Critical flaw in Nvidia's NeMo Gen-AI framework

The company released a patch to the NeMo GitHub repository and urged users to upgrade all instances to version r2.0.0rc0 or later.

Nvidia NeMo is used to streamline the development of custom genetic AI that includes large language models (LLM), multimodal AI, vision, and speech.

It provides tools to enterprises looking to build custom Gen-AI products with capabilities for refinement, model training, and inference across platforms ranging from data centers to edge devices.

See also: Apple, NVIDIA and Anthropic used YouTube videos illegally for AI training

The Nvidia NeMo framework helps developers efficiently create, adapt, and deploy new AI production models, leveraging existing code and pre-trained model checkpoints.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS