Base Command Manager (Linux): Local privesc via insecure temporary file handling
CVSS 4.4CVE-2024-0139NVIDIA / GPU stackcurated
Impact
Local privesc via insecure temporary file handling
Who can reach it
Local user on a managed node
What to do
Patch Base Command Manager on head and compute nodes
References
Related entries
- CUDA Toolkit: DoS via malformed string parsingCVE-2025-23247 · CUDA ToolkitMedium
- GPU Display Driver: Info disclosure (buffer over-read)CVE-2025-23286 · GPU Display DriverMedium
- NVIDIA Triton Inference Server: A specific model configuration plus a specific input causes an underflowCVE-2025-23335 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: Loading a misconfigured model causes a denial of serviceCVE-2025-23336 · NVIDIA Triton Inference ServerMedium
- NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko): An out-of-bounds read in theCVE-2025-23345 · NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko)Medium
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: Unexpected memory buffer operations in SROOT firmwareCVE-2025-33195 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.