Database/Firmware, BMC & network fabric
NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attacker
Impact
An attacker who already holds privileged access on the host can drive an out-of-bounds write in system firmware. NVIDIA scores this with a changed scope and high confidentiality, integrity and availability impact, meaning the write reaches components outside the OS's control. Firmware-level code execution survives reinstalling the operating system, so a box you believe was hit is not cleaned by reimaging - it needs the firmware reflashed. That is the real cost here: the remediation is a firmware update with the machine out of service, not a package upgrade.
Who can reach it
Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.
What to do
Take the fixed firmware version from NVIDIA product-security bulletin 5867 - the CVE record does not name one, so do not assume a version. Applying it means flashing DGX Spark system firmware with the machine out of service through at least one full power cycle. There is no in-band mitigation short of restricting who holds administrative access to the host.
References
Related entries
- NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attackerCVE-2026-24263 · NVIDIA DGX Spark system firmwareHigh
- NVIDIA DGX Spark firmware: second out-of-bounds write reachable by a privileged local attackerCVE-2026-47626 · NVIDIA DGX Spark system firmwareHigh
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theCVE-2026-43466 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingCVE-2026-6484 · Insyde InsydeH2O (unverified firmware volume in the boot chain)High
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theCVE-2013-3619 · Supermicro IPMI BMC firmwareHigh
- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soCVE-2014-8272 · Dell iDRAC6/iDRAC7 IPMI 1.5 session handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.