CNNVD-202512-1244 Information

CNNVD ID

CNNVD-202512-1244

CVE-2025-33213

  • CNNVD Published: 2025-12-09

Description (Chinese)

NVIDIA Merlin Transformers4Rec是美国英伟达(NVIDIA)公司的一个用于构建序列化和会话式推荐系统的软件。 NVIDIA Merlin Transformers4Rec存在代码问题漏洞,该漏洞源于Trainer组件存在反序列化问题,可能导致代码执行、拒绝服务、信息泄露和数据篡改。

Description (English)

NVIDIA Merlin Transformers4Rec is a software for the construction of a serialization and session-style referral system at NVIDIA. NVIDIA Merlin Transformers4Rec has a code loophole, which stems from the inverse sequence of the Trainer component, which may lead to code execution, denial of services, information leaks and data manipulation.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

英伟达

Published

2025-12-09

Last Modified

2026-02-24

References

https://nvd.nist.gov/vuln/detail/CVE-2025-33213 https://nvidia.custhelp.com/app/answers/detail/a_id/5739 https://www.cve.org/CVERecord?id=CVE-2025-33213

Patch

https://nvidia.custhelp.com/app/answers/detail/a_id/5739

Share on: