GPU VulnDB

Database/NVIDIA / GPU stack

DGX A100 BMC: unauthenticated stack overflow in the host KVM daemon leads to RCE

CVSS 9.8CVE-2023-31024NVIDIA / GPU stack+1 more CVEscurated

Impact

An unauthenticated attacker who can reach the BMC network interface can corrupt stack memory in the host KVM daemon with a crafted packet, leading to arbitrary code execution on the BMC, denial of service, information disclosure and data tampering. NVIDIA split this one KVM-daemon stack-corruption class across 2 CVE ids in security bulletin 5510; there is no separate action for either id.

Who can reach it

Network-adjacent mgmt-LAN attacker

What to do

Flash DGX A100 BMC firmware 00.22.05 or later out-of-band, and keep the BMC on an isolated management VLAN unreachable from tenant or general networks.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2023-31030

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.