Mellanox OFED: Authentication bypass in the host networking stack
CVSS 7.6CVE-2025-23263NVIDIA / GPU stackcurated
Impact
Authentication bypass in the host networking stack
Who can reach it
Network-adjacent attacker
What to do
Upgrade MLNX_OFED / DOCA-Host on all nodes; driver reload requires node drain
References
Related entries
- NVIDIA NVDebug tool: NVDebug can be induced to write files into restricted components, reaching data tamperingCVE-2025-23343 · NVIDIA NVDebug toolHigh
- NVIDIA Jetson Linux (UEFI): UEFI accepts a Linux Device Tree without checking authorization, so anyone who reachesCVE-2025-33182 · NVIDIA Jetson Linux (UEFI)High
- NVIDIA NeMo Agent Toolkit (Web UI): The chat API endpoint is vulnerable to server-side request forgery, so an attackerCVE-2025-33203 · NVIDIA NeMo Agent Toolkit (Web UI)High
- NVIDIA Jetson Linux (initrd command-line handling): An attacker with physical access and no credentials at all canCVE-2026-24154 · NVIDIA Jetson Linux (initrd command-line handling)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can craft microcode that the GPU's internalCVE-2021-23201 · NVIDIA GPU firmware microcontroller (Falcon)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can time a DMA write from the GPU's internalCVE-2021-23217 · NVIDIA GPU firmware microcontroller (Falcon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.