NVIDIA ConnectX / BlueField: Privilege escalation leading to arbitrary code execution via the management interface
CVE-2025-23299NVIDIA / GPU stackcurated
Impact
Privilege escalation leading to arbitrary code execution via the management interface
Who can reach it
Local
What to do
NIC/DPU firmware update
Fleet impact
How widespread
Universal on RDMA/InfiniBand fleets - ConnectX is the standard NIC in GPU clusters
Cost to remediate
firmware-flash on every NIC; requires a node reboot and in some fleets a maintenance window per rack
Why it hits the whole fleet
Arbitrary code execution in the NIC/DPU management interface: the NIC sees all inter-node RDMA traffic for training jobs, so a compromise reads or corrupts gradients across tenants
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.