Buffer Access with Incorrect Length Value Affecting triton-inference-server/server package, versions [,2.59.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TRITONINFERENCESERVERSERVER-13641138
  • published20 Oct 2025
  • disclosed6 Aug 2025
  • creditTrend Micro ZDI

Introduced: 6 Aug 2025

CVE-2025-23318  (opens in a new tab)
CWE-805  (opens in a new tab)

How to fix?

Upgrade triton-inference-server/server to version 2.59.1 or higher.

Overview

Affected versions of this package are vulnerable to Buffer Access with Incorrect Length Value via the MessageQueueShm class in the bundled Python backend. An attacker could cause an out-of-bounds write by sending a specially crafted request, leading to information disclosure, denial of service, or remote code execution, through corruption of existing data structures within the backend's shared memory.

Note: This vulnerability is only exploitable when using the default bundled Python backend /backends/python/libtriton_python.so.

Workaround

It is possible to update the Python backend to a patched version independently of the Triton Server; See Triton Inference Server Backend.

CVSS Base Scores

version 4.0
version 3.1