NVIDIA DGX-2 - SBIOS / SMM firmware: Privileged code can modify the ServerSetup NVRAM variable at runtime, altering
Impact
Privileged code can modify the ServerSetup NVRAM variable at runtime, altering platform configuration below the OS. This is firmware-level persistence: it survives OS reinstall, image re-flash and tenant handoff, and it is invisible to anything running above it. On a bare-metal GPU rental business it is the difference between wiping a node between tenants and not actually being able to.
Who can reach it
Local and already privileged - host root, or code that has reached the platform firmware/SMM path. It is not a first foothold; it is what turns a one-time root compromise into something you cannot remediate by reimaging.
What to do
Flash the fixed SBIOS from bulletin 5449. Cost: not live-patchable. Full node drain, host power cycle, and on DGX the SBIOS ships inside a firmware bundle alongside BMC and CPLD components, so budget 30-60 minutes of node downtime plus a post-flash health check. Firmware rollback protection means you cannot cleanly revert - stage on one node before the fleet.
References
Related entries
- NVIDIA DGX-2 - SBIOS / SMM firmware: An out-of-bounds write in the Bds phase gives a privileged local user firmwareCVE-2023-0201 · NVIDIA DGX-2 - SBIOS / SMM firmwareMedium
- NVIDIA DGX-2 - SBIOS / SMM firmware: An out-of-bounds access in the OFBD SMM handler against a preconditioned heapCVE-2023-0200 · NVIDIA DGX-2 - SBIOS / SMM firmwareHigh
- NVIDIA DGX-1 - SBIOS / SMM firmware: An out-of-bounds access in the Ofbd handler in the AMI SBIOS reaches SMM codeCVE-2023-25506 · NVIDIA DGX-1 - SBIOS / SMM firmwareHigh
- DGX A100 / A800 SBIOS: Code execution + privesc in SBIOSCVE-2023-25521 · DGX A100 / A800 SBIOSHigh
- DGX A100 / A800 SBIOS: DoS / data tampering / info disclosureCVE-2023-25522 · DGX A100 / A800 SBIOSHigh
- Cumulus Linux (switch OS): Cross-tenant info disclosure (VxLAN IPv6 mis-forwarding on SVI)CVE-2023-25525 · Cumulus Linux (switch OS)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.