NVIDIA DOCA: Local privesc via insecure file permissions
CVSS 7.3CVE-2025-23257NVIDIA / GPU stackcurated
Impact
Local privesc via insecure file permissions
Who can reach it
Local user on the DPU/host
What to do
Upgrade DOCA packages; restart DPU services
References
Related entries
- NVIDIA DOCA: Local privesc via insecure file permissionsCVE-2025-23258 · NVIDIA DOCAHigh
- GPU Display Driver: Access-control bypassCVE-2025-23277 · GPU Display DriverHigh
- NVIDIA NVDebug tool: NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching codeCVE-2025-23344 · NVIDIA NVDebug toolHigh
- Cumulus Linux / NVOS: Command injection (local)CVE-2025-33181 · Cumulus Linux / NVOSHigh
- NVIDIA NeMo Framework: A predefined variable pulls in functionality from an untrusted control sphere, reaching codeCVE-2025-33205 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Loading a maliciously crafted model file bypasses the framework's control mechanisms and reachesCVE-2025-33212 · NVIDIA NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.