RISC-V ISA (MTVEC register) as used in NVIDIA GPU microcontrollers: A documented ambiguity in the RISC-V specification
Impact
A documented ambiguity in the RISC-V specification leaves the machine trap vector base address register in an undefined state at reset, which fault injection can exploit to redirect trap handling and break the secure boot chain of an embedded microcontroller. NVIDIA's own offensive-security team assigned this; it is relevant because modern NVIDIA GPU and platform microcontrollers are RISC-V based, so it describes a weakness in the root of trust below the GPU driver. Exploitation needs physical glitching, not remote access - so it belongs in your supply-chain and physical-security threat model, not your patch queue.
Who can reach it
An attacker with physical access to the board who can perform voltage or clock glitching. Not reachable from software, local or remote.
What to do
Architectural ambiguity in the RISC-V ISA specification as implemented in embedded microcontrollers, including NVIDIA's. There is no operator-installable patch: the fix is in silicon and in hardened boot firmware from the chip vendor. For an operator this is unpatchable in the field - mitigate by treating physical access to a GPU as game over, keeping fault-injection-capable access (open chassis, exposed board) out of shared-tenancy racks, and preferring hardware generations that NVIDIA states carry the hardened boot ROM.
References
Related entries
- DGX A100 BMC: unauthenticated stack overflow in the host KVM daemon leads to RCECVE-2023-31024 · DGX A100 BMCCritical
- Base Command Manager (CMDaemon): Unauthenticated RCE on the cluster managerCVE-2024-0138 · Base Command Manager (CMDaemon)Critical
- NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker codeCVE-2025-33222 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: Execution with unnecessary privileges lets an unauthenticated network attacker reach codeCVE-2025-33223 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: A second over-privileged execution path with the same unauthenticated network reach and 9.8CVE-2025-33224 · NVIDIA Isaac LaunchableCritical
- NVIDIA FLARE SDK: Unauthenticated remote code executionCVE-2026-24178 · NVIDIA FLARE SDKCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.