GPU VulnDB

Database/NVIDIA / GPU stack

Megatron-Bridge: code injection via malicious input in the data merging and data shuffling tutorials

CVSS 7.8CVE-2025-33239NVIDIA / GPU stack+1 more CVEscurated

Impact

A local user with low privileges who can supply input to the data merging or data shuffling tutorial scripts gets code execution, privilege escalation, information disclosure and data tampering (CVSS 7.8, AV:L/AC:L/PR:L/UI:N/C:H/I:H/A:H). NVIDIA split the same tutorial code-injection class across 2 ids, one per affected tutorial. Note the earlier database wording of 'unsafe pickle deserialization' was wrong: the vendor classifies both as CWE-94 code injection.

Who can reach it

Malicious checkpoint

What to do

Upgrade Megatron-Bridge to 0.2.2 or later (all prior versions affected) and rebuild any training images that embed it; one upgrade closes both ids.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2025-33240

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.