¡¾¸´ÏÖ¡¿NVIDIA NeMo AI¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-23303/23304£©
Ðû²¼Ê±¼ä 2025-08-29NVIDIA NeMoÊÇÒ»¸öÃæÏòÌìÉúʽAIµÄ¿ò¼Ü£¬£¬£¬£¬Ö§³Ö´óÓïÑÔÄ£×Ó¡¢¶àģ̬ģ×ÓÒÔ¼°ÓïÒôAI¡£¡£ËüÌṩÁËѵÁ·¡¢Î¢Ðµ÷°²ÅÅÄ£×ӵŤ¾ß£¬£¬£¬£¬Í¬Ê±¿ÉÒÔ»ùÓÚÏÖÓдúÂëºÍԤѵÁ·Ä£×Ó¼ì²éµãÀ´½¨ÉèºÍ¶¨ÖÆÐ嵀 AI Ä£×Ó¡£¡£
8ÔÂ11ÈÕ£¬£¬£¬£¬NVIDIA¹Ù·½Ðû²¼Ò»ÌõÇ徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÁ½¸öNeMo¿ò¼ÜµÄ¸ßΣÎó²î£¨CVE-2025-23303ºÍCVE-2025-23304£©£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚ¼ÓÔØÄ£×ÓʱִÐÐí§Òâ´úÂë¡£¡£Îª×èÖ¹¸ÃÎó²î´øÀ´µÄÇ徲Σº¦£¬£¬£¬£¬½¨ÒéÏà¹ØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£¡£
Ó°Ïì°æ±¾
NVIDIA NeMo Framework <2.3.2
Îó²î³ÉÒò
CVE-2025-23303
µ±Ê¹ÓÃÊÜÏÞÖÆµÄ·´ÐòÁл¯»úÖÆ£¨RestrictedUnpickler£©¼ÓÔØ¾ÓÉѹËõºóµÄÄ£×ÓÊý¾Ýʱ£¬£¬£¬£¬»á´¥·¢UnpicklingError¡£¡£¿£¿ò¼ÜÔÚ²¶»ñ¸ÃÒì³£ºó£¬£¬£¬£¬Í¨¹ýjoblib.loadÖØÐ¼ÓÔØÄ£×ÓÊý¾Ý¡£¡£ÓÉÓÚ´Ëʱ²»ÔÙÊܵ½RestrictedUnpicklerµÄÏÞÖÆ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»ÐÐΪ£¬£¬£¬£¬½«È«ÐĽṹµÄÄ£×ÓÎļþ¼ÓÔØµ½ÏµÍ³ÖУ¬£¬£¬£¬´Ó¶ø´¥·¢í§Òâ´úÂëÖ´ÐС£¡£
CVE-2025-23304
ÔÚNeMo¿ò¼ÜÖУ¬£¬£¬£¬ÑµÁ·Àú³Ì»áƾ֤ÉèÖÃÎļþ¶¯Ì¬½¨ÉèºÍ³õʼ»¯Ä£×Ó×é¼þ¡£¡£ÈôÊÇÉèÖÃÎļþÖаüÀ¨¶ñÒâ½á¹¹µÄÀà»ò²ÎÊý£¬£¬£¬£¬¿ò¼ÜÔÚʵÀý»¯Ïà¹Ø×é¼þʱ½«»áÖ´ÐÐÆäÖеĶñÒâ´úÂë¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÉèÖÃÎļþ£¬£¬£¬£¬ÔÚÄ£×ÓѵÁ·»ò΢µ÷½×¶Î´¥·¢í§Òâ´úÂëÖ´ÐС£¡£
Îó²î¸´ÏÖ
CVE-2025-23303

CVE-2025-23304

ÐÞ¸´½¨Òé
NVIDIA¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬Ç뾡¿ìÏÂÔØ2.3.2°æ±¾ÐÞ¸´Îó²î¡£¡£
[1]https://nvidia.custhelp.com/app/answers/detail/a_id/5686
[2]https://github.com/NVIDIA-NeMo/NeMo/releases/tag/v2.3.2
ÄϹ¬NGÓéÀÖÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î6500Óà¸ö£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢AI+Çå¾²Ñо¿¡¢ÎÀÐÇÇå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·À¶Ô¿¹ÊÖÒÕÑо¿¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£



¾©¹«Íø°²±¸11010802024551ºÅ