NVIDIA BlueField: Privilege escalation from incorrect user management on the DPU
CVSS 7.8CVE-2023-25519NVIDIA / GPU stackcurated
Impact
Privilege escalation from incorrect user management on the DPU
Who can reach it
Local
What to do
BlueField DOCA/BFB update; requires draining the node because the DPU carries the tenant's network path
References
Related entries
- DGX H100 BMC: Kernel memory corruptionCVE-2023-25527 · DGX H100 BMCHigh
- GPU Display Driver (Windows): Local privesc via named-pipe server accessCVE-2023-31019 · GPU Display Driver (Windows)High
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface: A use-after-free in the amdgpu GEM/VM/command-submissionCVE-2023-51042 · Linux kernel amdgpu GEM/VM/command-submission ioctl surfaceHigh
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A correctness defect in the amdgpu display core (DC/DM)CVE-2023-52624 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm): A double free in the amdgpu power managementCVE-2023-52691 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm)High
- Linux kernel amdgpu kernel driver core (drm/amd): An out-of-bounds access in the amdgpu kernel driver core - a lengthCVE-2023-52812 · Linux kernel amdgpu kernel driver core (drm/amd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.