CVE-2026-47620
Analyzed Analyzed - Analysis Complete

Race Condition in NVIDIA Dynamo for Linux Leads to DoS

Vulnerability report for CVE-2026-47620, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-07

Assigner: NVIDIA Corporation

Description

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-07
Generated
2026-08-25
AI Q&A
2026-08-04
EPSS Evaluated
2026-08-23
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nvidia dynamo to 1.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA Dynamo for Linux has a race condition vulnerability in the LoRA manager singleton initialization. This flaw allows an attacker to exploit improper synchronization during concurrent execution, potentially leading to data tampering and denial of service.

Detection Guidance

Detection of this vulnerability requires checking for race conditions in the LoRA manager singleton initialization within NVIDIA Dynamo for Linux. Monitor logs for unexpected data tampering or service disruptions. Review synchronization mechanisms in the codebase for improper handling of shared resources. No specific commands are provided in the given context.

Impact Analysis

An attacker could tamper with data or disrupt services by exploiting this race condition. This may cause system instability, unauthorized data changes, or service unavailability, particularly in environments using NVIDIA Dynamo for Linux.

Compliance Impact

This vulnerability could lead to data tampering or denial of service, which may violate compliance requirements for data integrity and availability under standards like GDPR and HIPAA. Organizations must address this flaw to maintain regulatory compliance.

Mitigation Strategies

Update NVIDIA Dynamo for Linux to the latest version beyond v1.2.0 to address the race condition in the LoRA manager singleton initialization. Monitor for unusual data tampering or denial of service events as potential indicators of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47620. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart