CVE-2026-47620
Received Received - Intake

Race Condition in NVIDIA Dynamo for Linux Leads to DoS

Vulnerability report for CVE-2026-47620, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: NVIDIA Corporation

Description

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nvidia dynamo_for_linux to 1.2.0 (inc)
nvidia dynamo *-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA Dynamo for Linux has a race condition vulnerability in the LoRA manager singleton initialization. This flaw allows an attacker to exploit improper synchronization during concurrent execution, potentially leading to data tampering and denial of service.

Impact Analysis

An attacker could tamper with data or disrupt services by exploiting this race condition. This may cause system instability, unauthorized data changes, or service unavailability, particularly in environments using NVIDIA Dynamo for Linux.

Compliance Impact

This vulnerability could lead to data tampering or denial of service, which may violate compliance requirements for data integrity and availability under standards like GDPR and HIPAA. Organizations must address this flaw to maintain regulatory compliance.

Mitigation Strategies

Update NVIDIA Dynamo for Linux to the latest version beyond v1.2.0 to address the race condition in the LoRA manager singleton initialization. Monitor for unusual data tampering or denial of service events as potential indicators of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47620. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart