From e09ba7938efde6e75fefb77d4602a10b88ba0620 Mon Sep 17 00:00:00 2001 From: "M. Chornyi" <99709299+mc-nv@users.noreply.github.com> Date: Fri, 2 Oct 2026 20:58:10 +0000 Subject: [PATCH] docs: Add SECURITY.md TRI-1935 --- SECURITY.md | 143 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 143 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..5672548 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,143 @@ + + +# Security Policy + +## Reporting a Vulnerability + +Please do **not** report security vulnerabilities through public GitHub +issues, discussions, or pull requests. + +To report a potential security vulnerability in any NVIDIA product, use one of +the following channels: + +1. **NVIDIA Vulnerability Disclosure Program** (preferred): + +2. **Email:** [psirt@nvidia.com](mailto:psirt@nvidia.com). Please encrypt + sensitive reports with NVIDIA's public PGP key: + +3. **GitHub Private Vulnerability Reporting:** use the "Report a + vulnerability" button on this repository's **Security** tab, where enabled. + +Please include: + +1. Product name and version, branch, or commit that contains the + vulnerability. +2. Type of vulnerability (for example code execution, denial of service, + buffer overflow, path traversal). +3. Step-by-step instructions to reproduce the issue. +4. Proof-of-concept or exploit code, if available. +5. Potential impact, including how an attacker could exploit the issue. + +NVIDIA PSIRT acknowledges reports, assesses them, and coordinates fixes and +disclosure with the reporter. OEM partners should contact their NVIDIA +Customer Program Manager. Past bulletins are listed at +. + +## Security Architecture and Context + +**Project:** Triton Developer Tools, a set of helper libraries and tooling +for building applications on top of the Triton Inference Server. + +**Classification:** Library / SDK, plus build and development tooling. It is +not a network service and does not open listening sockets itself. + +**Components:** + +- `server/` is a C++17 wrapper library (`TritonServer`, `InferRequest`, + `InferResult`, and a trace manager) over the in-process Triton Server C API + (`libtritonserver`), with example programs and a unit test. +- `tools/add_copyright.py` and `.pre-commit-hooks.yaml` provide the + `add-license` pre-commit hook used by Triton repositories. It reads and + rewrites source files in the repository where it runs. +- `server/install_dependencies_and_build.sh` installs build dependencies and + builds the wrapper. +- `qa/` contains test scripts and sample Python model fixtures. + +**Primary security responsibility:** correct handling of caller-supplied model +repository paths, tensor buffers, memory types, and trace file paths when +passing them to the Triton core library, and safe, bounded file modification +by the license hook. + +**Key boundaries and interfaces:** + +- The public C++ API in `server/include/triton/developer_tools/`. +- Pre-commit hook invocation with file paths supplied by pre-commit. +- Build-time package installation and downloads. + +**Repository Exposure Classification:** Public. Basis: the repository is +publicly visible on GitHub. + +**Service Exposure Classification:** Internal-Isolated, medium confidence. +Basis: the code is an embedded library and developer tool with no network +listeners and no authentication surface of its own. Exposure is inherited +from the application that embeds it. + +## Threat Model + +1. **Untrusted model repository or model content:** `TritonServer::Create` + accepts a model repository path from the embedding application. A + repository containing a malicious model or backend library can execute + code in the host process, because models and backends are loaded + in-process. +2. **Unsafe buffer and memory handling in the tensor API:** `InferRequest` + and `Tensor` accept caller-provided buffers, sizes, data types, and memory + types (CPU, pinned, GPU). Mismatched sizes or types supplied by a caller + can lead to out-of-bounds reads or writes in the C++ wrapper. +3. **Trace file path abuse:** the trace manager in `server/src/tracer.cc` + writes trace output to caller-supplied file paths. An attacker who + controls that path or its location may overwrite files or cause + unbounded disk usage through a high trace rate. +4. **Unintended file modification by the license hook:** + `tools/add_copyright.py` rewrites files in place. Running it on untrusted + or unexpected paths, or through symlinks, can modify files outside the + intended repository. +5. **Build-time supply chain:** `server/install_dependencies_and_build.sh` + adds an external package repository and signing key and installs a pinned + CMake version. Compromise of that source or of the build base image would + affect built artifacts. +6. **Pre-commit consumers pinned by tag:** downstream repositories consume + the `add-license` hook by tag. Replacing or moving a tag would change code + executed on every contributor's machine and in CI. + +## Critical Security Assumptions + +- The embedding application is trusted and is responsible for authenticating + and authorizing its own users. This library provides no authentication, + authorization, or TLS. +- Model repositories, backends, and shared libraries loaded by Triton come + from trusted sources. The library does not verify their integrity. +- Callers validate tensor shapes, sizes, data types, and memory types before + passing them to the wrapper. +- Trace file paths are chosen by the application operator and are not + attacker-controlled. The destination has sufficient disk space and + appropriate permissions. +- The license hook runs only against files inside a trusted working tree. +- Build environments, base images, and package mirrors used for + `install_dependencies_and_build.sh` are trusted. +- Release tags are write-once and are not moved after publication.