NVIDIA DGX-1 - SBIOS / SMM firmware: A flaw in the Bds phase reaches firmware code execution and privilege escalation
Impact
A flaw in the Bds phase reaches firmware code execution and privilege escalation. This is firmware-level persistence: it survives OS reinstall, image re-flash and tenant handoff, and it is invisible to anything running above it. On a bare-metal GPU rental business it is the difference between wiping a node between tenants and not actually being able to.
Who can reach it
Local and already privileged - host root, or code that has reached the platform firmware/SMM path. It is not a first foothold; it is what turns a one-time root compromise into something you cannot remediate by reimaging.
What to do
Flash the fixed SBIOS from bulletin 5458. Cost: not live-patchable. Full node drain, host power cycle, and on DGX the SBIOS ships inside a firmware bundle alongside BMC and CPLD components, so budget 30-60 minutes of node downtime plus a post-flash health check. Firmware rollback protection means you cannot cleanly revert - stage on one node before the fleet.
References
Related entries
- NVIDIA DGX-1 - SBIOS / SMM firmware: The Uncore PEI module never authenticates the code executed by SSA, soCVE-2023-0209 · NVIDIA DGX-1 - SBIOS / SMM firmwareHigh
- NVIDIA DGX-1 - SBIOS / SMM firmware: An out-of-bounds access in the Ofbd handler in the AMI SBIOS reaches SMM codeCVE-2023-25506 · NVIDIA DGX-1 - SBIOS / SMM firmwareHigh
- vGPU software (Virtual GPU Manager): Host-side DoS (null deref in vGPU Manager)CVE-2023-31026 · vGPU software (Virtual GPU Manager)Medium
- NVIDIA GPU secure microcontroller: incorrect permissions let privileged local access modify protected memoryCVE-2026-47518 · NVIDIA GPU secure microcontroller (permission assignment for protected memory)Medium
- NVIDIA Triton Inference Server: Manipulating the Python backend's shared memory region produces an out-of-bounds readCVE-2025-23333 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: A crafted request causes an out-of-bounds read in the Python backend, disclosing memoryCVE-2025-23334 · NVIDIA Triton Inference ServerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.