DGX A100 / A800 SBIOS: DoS / data tampering / info disclosure
CVSS 7.5CVE-2023-25522NVIDIA / GPU stackcurated
Impact
DoS / data tampering / info disclosure
Who can reach it
Local operator / compromised host OS
What to do
Flash SBIOS 1.21; node drain + power cycle
References
Related entries
- DGX A100 / A800 SBIOS: Code execution + privesc in SBIOSCVE-2023-25521 · DGX A100 / A800 SBIOSHigh
- Cumulus Linux (switch OS): Cross-tenant info disclosure (VxLAN IPv6 mis-forwarding on SVI)CVE-2023-25525 · Cumulus Linux (switch OS)High
- DGX A100 SBIOS: Improper crypto config / UI-layer restriction in SBIOSCVE-2023-31032 · DGX A100 SBIOSHigh
- DGX A100 SBIOS: Improper input validation in SBIOSCVE-2023-31035 · DGX A100 SBIOSHigh
- Triton Inference Server: RCE / privesc / data tampering via model-load path traversal (`--model-control explicit`)CVE-2023-31036 · Triton Inference ServerHigh
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): A NULL pointer dereference in the amdgpuCVE-2023-52883 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.