NVIDIA MLNX_DPDK: Improper error recovery in NVIDIA's DPDK distribution lets a remote attacker cause denial of service
Impact
Improper error recovery in NVIDIA's DPDK distribution lets a remote attacker cause denial of service with some integrity and confidentiality impact. Relevant on DPDK-based storage and network dataplanes fronting GPU clusters.
Who can reach it
Network - the attacker sends traffic that the DPDK dataplane mishandles. No authentication involved; this is packet-level reachability.
What to do
Update MLNX_DPDK per bulletin 5389 and restart the dataplane application. Cost: a dataplane restart drops in-flight connections; on a storage path that means an I/O stall visible to running jobs, so drain or fail over first.
References
Related entries
- NVIDIA GPU Display Driver kernel mode layer: null-pointer dereferences allow local denial of serviceCVE-2022-34665 · NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko)Medium
- NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko): An unprivileged userCVE-2022-34678 · NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko)Medium
- DGX-2 BMC: Info disclosure via path traversalCVE-2022-42282 · DGX-2 BMCMedium
- ConnectX-5/6/6-DX NIC firmware: NIC DoS (improper exception handling)CVE-2023-0204 · ConnectX-5/6/6-DX NIC firmwareMedium
- Cumulus Linux (neighmgrd/nlmanager): Switch DoS via crafted packetCVE-2023-25526 · Cumulus Linux (neighmgrd/nlmanager)Medium
- DGX H100 BMC (IPMI): Info disclosure of credentialsCVE-2023-25532 · DGX H100 BMC (IPMI)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.