GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA ConnectX / BlueField: Privilege escalation leading to arbitrary code execution via the management interface

CVE-2025-23299NVIDIA / GPU stackcurated

Impact

Privilege escalation leading to arbitrary code execution via the management interface

Who can reach it

Local

What to do

NIC/DPU firmware update

Fleet impact

How widespread

Universal on RDMA/InfiniBand fleets - ConnectX is the standard NIC in GPU clusters

Cost to remediate

firmware-flash on every NIC; requires a node reboot and in some fleets a maintenance window per rack

Why it hits the whole fleet

Arbitrary code execution in the NIC/DPU management interface: the NIC sees all inter-node RDMA traffic for training jobs, so a compromise reads or corrupts gradients across tenants

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.