Nsight Graphics: Local code exec via command injection
CVSS 7.8CVE-2025-33206NVIDIA / GPU stackcurated
Impact
Local code exec via command injection
Who can reach it
Unprivileged local user on a dev node
What to do
Upgrade Nsight packages in dev images
References
Related entries
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2025-33217 · GPU Display DriverHigh
- GPU Display Driver: Kernel mode layer integer overflows allow local privilege escalationCVE-2025-33218 · GPU Display DriverHigh
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A malicious guest causes the VirtualCVE-2025-33220 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA NeMo Framework: Crafted data reaches code injection and privilege escalation in the job contextCVE-2025-33226 · NVIDIA NeMo FrameworkHigh
- Merlin Transformers4Rec: RCE via unsanitized inputCVE-2025-33233 · Merlin Transformers4RecHigh
- NVIDIA runx: Arbitrary command exec via shell metacharacter injectionCVE-2025-33234 · NVIDIA runxHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.