GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attacker

CVE-2026-24263Firmware, BMC & network fabriccurated

Impact

A privileged local attacker can trigger a NULL pointer dereference in system firmware. NVIDIA lists denial of service alongside code execution, privilege escalation, information disclosure and data tampering, and scores the scope as changed - a firmware fault here takes the machine down rather than a process. Practically, the availability half is the one you can count on: the box stops, and it stops below the level any host-side watchdog or orchestrator can recover. It ships in the same bulletin as the two out-of-bounds write issues, so it is fixed by the same firmware update rather than separately.

Who can reach it

Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.

What to do

Fixed firmware version comes from NVIDIA product-security bulletin 5867; the CVE record states none. Flash DGX Spark system firmware with the machine out of service. This bulletin covers CVE-2026-24262, CVE-2026-24263 and CVE-2026-47626 together, so schedule one flash window, not three.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.