GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attacker

CVE-2026-24262Firmware, BMC & network fabriccurated

Impact

An attacker who already holds privileged access on the host can drive an out-of-bounds write in system firmware. NVIDIA scores this with a changed scope and high confidentiality, integrity and availability impact, meaning the write reaches components outside the OS's control. Firmware-level code execution survives reinstalling the operating system, so a box you believe was hit is not cleaned by reimaging - it needs the firmware reflashed. That is the real cost here: the remediation is a firmware update with the machine out of service, not a package upgrade.

Who can reach it

Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.

What to do

Take the fixed firmware version from NVIDIA product-security bulletin 5867 - the CVE record does not name one, so do not assume a version. Applying it means flashing DGX Spark system firmware with the machine out of service through at least one full power cycle. There is no in-band mitigation short of restricting who holds administrative access to the host.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.