Apex: Remote RCE via unsafe pickle deserialization
CVSS 9.0CVE-2025-33244NVIDIA / GPU stackcurated
Impact
Remote RCE via unsafe pickle deserialization
Who can reach it
Network attacker / malicious checkpoint
What to do
Bump Apex in training images; rebuild and redeploy
References
Related entries
- NVIDIA BlueField - VIRTIO-Net emulation: A VM user sends a crafted message to the BlueField VIRTIO-Net device and getsCVE-2026-65094 · NVIDIA BlueField - VIRTIO-Net emulationCritical
- ConnectX / BlueField firmware: Improper certificate validationCVE-2024-0105 · ConnectX / BlueField firmwareHigh
- NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device node: The GPU-side twin ofCVE-2012-0946 · NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device nodeHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Any local account on a Windows GPU host can call the driver's escapeCVE-2018-6247 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel read/write from an unprivileged escape callCVE-2018-6248 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): NULL dereference in the kernel-mode layer reachableCVE-2018-6249 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.