NVIDIA ConnectX / BlueField: Privilege escalation leading to arbitrary code execution via the management interface
CVSS 6.7CVE-2025-23299NVIDIA / GPU stackcurated
Impact
Privilege escalation leading to arbitrary code execution via the management interface
Who can reach it
Local
What to do
NIC/DPU firmware update
Fleet impact
How widespread
Universal on RDMA/InfiniBand fleets - ConnectX is the standard NIC in GPU clusters
Cost to remediate
firmware-flash on every NIC; requires a node reboot and in some fleets a maintenance window per rack
Why it hits the whole fleet
Arbitrary code execution in the NIC/DPU management interface: the NIC sees all inter-node RDMA traffic for training jobs, so a compromise reads or corrupts gradients across tenants
References
Related entries
- HGX / DGX GB200, GB300, B300 (BMC -> HMC): BMC admin can pivot to the HMC as administratorCVE-2025-23337 · HGX / DGX GB200, GB300, B300 (BMC -> HMC)Medium
- NVIDIA Nsight Graphics (ngfx component, Windows): An ngfx component resolves a DLL from an untrusted search path, soCVE-2025-23355 · NVIDIA Nsight Graphics (ngfx component, Windows)Medium
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A second out-of-bounds write in SROOT firmwareCVE-2025-33190 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
- CUDA Toolkit: Code exec via path manipulation on library loadCVE-2025-33231 · CUDA ToolkitMedium
- NVIDIA GPU driver: out-of-bounds writes in the kernel mode layer reachable by a privileged local userCVE-2026-47509 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds writes)Medium
- NVIDIA GPU driver: unbounded string operation in the kernel mode layer causes an out-of-bounds readCVE-2026-47515 · NVIDIA GPU Display Driver kernel mode layer (unbounded string operation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.