BlueField (GA firmware): out-of-bounds write in the VF command interface allows code execution on the DPU
Impact
A local user with virtual-function access can send crafted command-interface input that writes out of bounds, giving arbitrary code execution on the DPU firmware - below the host OS and outside tenant visibility. NVIDIA split this across 2 ids (CVE-2025-23350, CVE-2025-23351) in bulletin 5699; both are the same class of flaw in the same interface with the same fix. Highest risk where VFs are handed to untrusted tenants; where no VFs are exposed, only admin/hypervisor-level callers can reach it.
Who can reach it
Privileged network attacker on the DPU management path
What to do
Flash the fixed BlueField GA firmware from NVIDIA bulletin 5699 out-of-band once - it covers both ids. The DPU reset drops tenant networking, so drain the node first. Until then, stop assigning VFs to untrusted tenants.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA Isaac Lab: A deserialization flaw reaches code executionCVE-2025-33210 · NVIDIA Isaac LabCritical
- Apex: Remote RCE via unsafe pickle deserializationCVE-2025-33244 · ApexCritical
- NVIDIA BlueField - VIRTIO-Net emulation: A VM user sends a crafted message to the BlueField VIRTIO-Net device and getsCVE-2026-65094 · NVIDIA BlueField - VIRTIO-Net emulationCritical
- ConnectX / BlueField firmware: Improper certificate validationCVE-2024-0105 · ConnectX / BlueField firmwareHigh
- NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device node: The GPU-side twin ofCVE-2012-0946 · NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device nodeHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Any local account on a Windows GPU host can call the driver's escapeCVE-2018-6247 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.