NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A second resource-reuse path in SROOT firmware leaks
Impact
A second resource-reuse path in SROOT firmware leaks residual data. These sit in the GB10 root-of-trust chain, so a successful exploit undermines the platform's own attestation and secure-boot story rather than just the OS above it.
Who can reach it
Local access to the DGX Spark. Several of the set need no privileges at all; the rest need host root. This is a desk-side developer box, so physical and local access assumptions are much weaker than for a racked DGX.
What to do
Apply the DGX Spark firmware update from bulletin 5720. Cost: flash plus reboot, low drain cost given the form factor, but not live-patchable and root-of-trust firmware cannot be rolled back once applied.
References
Related entries
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: Incorrect control-flow behaviour in SROOT firmwareCVE-2025-33199 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareLow
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A third resource-reuse path in SROOT firmware leaksCVE-2025-33200 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareLow
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An attacker with privileged access reachesCVE-2025-33187 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareCritical
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An attacker tampers with hardware controls directlyCVE-2025-33188 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareHigh
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An out-of-bounds write in SROOT firmware reaches codeCVE-2025-33189 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareHigh
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A second out-of-bounds write in SROOT firmwareCVE-2025-33190 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.