BlueField-2 / BlueField-3 DPU BMC: Code injection on DPU BMC
CVSS 7.2CVE-2023-31037NVIDIA / GPU stackcurated
Impact
Code injection on DPU BMC -> DPU takeover below the host OS
Who can reach it
Network-adjacent mgmt access to the DPU BMC
What to do
Flash DPU BMC firmware out-of-band; DPU reset drops tenant networking, schedule drain
References
Related entries
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A kernel object created by the escape handler gets defaultCVE-2019-5687 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA vGPU Manager (vGPU plugin): The vGPU Manager grants a guest access to memory the guest does not own. That is theCVE-2019-5697 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied data size is not validated, letting a tenant tamper with host-sideCVE-2020-5970 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Uninitialised local pointers later freed in the vGPU plugin - a guest-triggered freeCVE-2020-5972 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin + host kernel module): The host can be made to write outside the frame-buffer regionCVE-2020-5983 · NVIDIA vGPU Manager (vGPU plugin + host kernel module)High
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied length not validated, allowing host-side data tampering or aCVE-2020-5985 · NVIDIA vGPU Manager (vGPU plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.