NVIDIA NVDebug tool: The NVDebug diagnostic collector lets an actor gain access to a privileged account, reaching code
Impact
The NVDebug diagnostic collector lets an actor gain access to a privileged account, reaching code execution and privilege escalation with a changed scope. NVDebug runs on DGX/HGX platform hosts and is exactly the tool an operator runs as root when something is already wrong.
Who can reach it
Local, low privileges, with user interaction - typically an operator running NVDebug on a node where an attacker already has an unprivileged foothold.
What to do
Update NVDebug per bulletin 5696. Cost: it is a standalone tool, so updating costs nothing operationally. The real control is to stop running old NVDebug bundles as root on nodes you already suspect are compromised.
References
Related entries
- NVIDIA NVDebug tool: NVDebug can be induced to write files into restricted components, reaching data tamperingCVE-2025-23343 · NVIDIA NVDebug toolHigh
- NVIDIA NVDebug tool: NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching codeCVE-2025-23344 · NVIDIA NVDebug toolHigh
- NVIDIA TensorRT: An out-of-bounds write reachable from the network reaches data tampering, scored 8.2 with noCVE-2026-24188 · NVIDIA TensorRTHigh
- NVIDIA CUDA-Q: Info disclosure / code exec (OOB read in circuit compilation)CVE-2026-24189 · NVIDIA CUDA-QHigh
- NVIDIA Dynamo: RCE via buffer overflow in tensor shape validationCVE-2026-24253 · NVIDIA DynamoHigh
- DCGM: DoS of the GPU telemetry/health daemon (resource exhaustion)CVE-2026-47483 · DCGMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.