GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches high

CVE-2025-23293NVIDIA / GPU stackcurated

Impact

An unauthorised action against the DLS reaches high integrity and availability impact with a changed scope - scored 8.7, the most serious of the licensing-appliance issues. An attacker on the management network can take the licensing service down or corrupt it, which eventually strands every vGPU guest.

Who can reach it

Adjacent network, low privileges, no user interaction. Any account on the management network reaches it.

What to do

Update the DLS appliance per bulletin 5705 as a priority, and segment the licensing appliance off the general management VLAN. Cost: appliance restart; plan it against your licence lease window so guests do not notice.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.