¡¾¸´ÏÖ¡¿NVIDIA NeMo AI¿ò¼ÜÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-23303/23304£©

°ä²¼¹¦·ò 2025-08-29

NVIDIA NeMoÊÇÒ»¸öÃæÏòÌìÉúʽAIµÄ¿ò¼Ü£¬Ö§³Ö´ó˵»°Ä£ÐÍ¡¢¶àģ̬ģÐÍÒÔ¼°ÓïÒôAI¡£ËüÌṩÁËѵÁ·¡¢Î¢ºÍг²¿ÊðÄ£Ð͵Ť¾ß£¬Í¬Ê±Äܹ»»ùÓÚÏÖÓдúÂëºÍԤѵÁ·Ä£ÐͲ鳭µãÀ´´´½¨ºÍ¶¨ÔìеĠAI Ä£ÐÍ¡£

8ÔÂ11ÈÕ£¬NVIDIA¹Ù·½°ä²¼Ò»Ìõ°²È«²¼¸æ£¬½¨¸´ÁËÁ½¸öNeMo¿ò¼ÜµÄ¸ßΣ·ì϶£¨CVE-2025-23303ºÍCVE-2025-23304£©£¬ÔÊÐí¹¥»÷ÕßÔÚ¼ÓÔØÄ£ÐÍʱִÐÐËÁÒâ´úÂ롣ΪԤ·À¸Ã·ì϶´øÀ´µÄ°²È«·çÏÕ£¬½¨ÒéÓйØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£


Ó°Ïì°æ±¾


NVIDIA NeMo Framework <2.3.2


·ì϶³ÉÒò


CVE-2025-23303


µ±Ê¹ÓÃÊÜÏ޶ȵķ´ÐòÁл¯»úÔ죨RestrictedUnpickler£©¼ÓÔØ¾­¹ýѹËõºóµÄÄ£ÐÍÊý¾Ýʱ£¬»á´¥·¢UnpicklingError¡ £¿ò¼ÜÔÚ²¶»ñ¸ÃÒì³£ºó£¬Í¨¹ýjoblib.load³ÁмÓÔØÄ£ÐÍÊý¾Ý¡£ÓÉÓÚ´Ëʱ²»ÔÙÊܵ½RestrictedUnpicklerµÄÏÞ¶È£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»ÐÐΪ£¬½«¾«ÐÄ»ú¹ØµÄÄ£ÐÍÎļþ¼ÓÔØµ½ÏµÍ³ÖУ¬´Ó¶ø´¥·¢ËÁÒâ´úÂëÖ´ÐС£


CVE-2025-23304


ÔÚNeMo¿ò¼ÜÖУ¬ÑµÁ·¹ý³Ì»áƾ¾ÝÅäÖÃÎļþ¶¯Ì¬´´½¨ºÍ³õʼ»¯Ä£ÐÍ×é¼þ¡£ÈôÊÇÅäÖÃÎļþÖÐÔ̺¬¶ñÒâ»ú¹ØµÄÀà»ò²ÎÊý£¬¿ò¼ÜÔÚÊ·ý»¯ÓйØ×é¼þʱ½«»áÖ´ÐÐÆäÖеĶñÒâ´úÂë¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÅäÖÃÎļþ£¬ÔÚÄ£ÐÍѵÁ·»ò΢µ÷½×¶Î´¥·¢ËÁÒâ´úÂëÖ´ÐС£


·ì϶¸´ÏÖ


CVE-2025-23303

ͼƬ1.png


CVE-2025-23304


ͼƬ2.png


½¨¸´½¨Òé


NVIDIA¹Ù·½ÒѰ䲼°²È«¹«¸æ²¢°ä²¼Á˽¨¸´°æ±¾£¬Ç뾡¿ìÏÂÔØ2.3.2°æ±¾½¨¸´·ì϶¡£


²Î¿¼Á´½Ó£º

[1]https://nvidia.custhelp.com/app/answers/detail/a_id/5686

[2]https://github.com/NVIDIA-NeMo/NeMo/releases/tag/v2.3.2



GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶6500Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢5G°²È«×êÑÓ×¢AI+°²È«×êÑÓ×¢ÎÀÐǰ²È«×êÑÓ×¢ÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÎÞÏß°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·ÀÆ¥µÐ¼¼Êõ×êÑС£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£


adlab.jpg