GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA DGX Station - SBIOS / SMM firmware: The same SmiFlash read/write/erase primitive on DGX Station, giving

CVE-2022-42277NVIDIA / GPU stackcurated

Impact

The same SmiFlash read/write/erase primitive on DGX Station, giving a privileged local user arbitrary control of the platform flash. This is firmware-level persistence: it survives OS reinstall, image re-flash and tenant handoff, and it is invisible to anything running above it. On a bare-metal GPU rental business it is the difference between wiping a node between tenants and not actually being able to.

Who can reach it

Local and already privileged - host root, or code that has reached the platform firmware/SMM path. It is not a first foothold; it is what turns a one-time root compromise into something you cannot remediate by reimaging.

What to do

Flash the fixed SBIOS from bulletin 5435. Cost: not live-patchable. Full node drain, host power cycle, and on DGX the SBIOS ships inside a firmware bundle alongside BMC and CPLD components, so budget 30-60 minutes of node downtime plus a post-flash health check. Firmware rollback protection means you cannot cleanly revert - stage on one node before the fleet.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.