NVIDIA Cumulus Linux: Improper privilege management in the user-management component lets an unprivileged switch user
CVSS 7.8CVE-2026-24183NVIDIA / GPU stackcurated
Impact
Improper privilege management in the user-management component lets an unprivileged switch user escalate to full switch administration.
Who can reach it
Local on the switch, unprivileged. Anyone with any shell account on the Cumulus switch - including read-only monitoring accounts.
What to do
Upgrade Cumulus Linux per bulletin 5817. Cost: switch reboot and link flap; sequence leaf-by-leaf so the fabric keeps ECMP paths. Audit who actually has shell on your switches while you are at it.
References
Related entries
- GPU Display Driver: Local privesc (insufficient permission checks)CVE-2026-24190 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (synchronization issue)CVE-2026-24191 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (integer overflow in address calc)CVE-2026-24192 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (buffer overflow in GPU command processing)CVE-2026-24193 · GPU Display DriverHigh
- GPU Display Driver / GPU firmware: Local privesc via improper GPU firmware parameter validationCVE-2026-24194 · GPU Display Driver / GPU firmwareHigh
- BioNeMo Framework: RCE via insecure deserialization on model loadCVE-2026-24216 · BioNeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.