Database/Firmware, BMC & network fabric
NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attacker
Impact
A privileged local attacker can trigger a NULL pointer dereference in system firmware. NVIDIA lists denial of service alongside code execution, privilege escalation, information disclosure and data tampering, and scores the scope as changed - a firmware fault here takes the machine down rather than a process. Practically, the availability half is the one you can count on: the box stops, and it stops below the level any host-side watchdog or orchestrator can recover. It ships in the same bulletin as the two out-of-bounds write issues, so it is fixed by the same firmware update rather than separately.
Who can reach it
Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.
What to do
Fixed firmware version comes from NVIDIA product-security bulletin 5867; the CVE record states none. Flash DGX Spark system firmware with the machine out of service. This bulletin covers CVE-2026-24262, CVE-2026-24263 and CVE-2026-47626 together, so schedule one flash window, not three.
References
Related entries
- NVIDIA DGX Spark firmware: second out-of-bounds write reachable by a privileged local attackerCVE-2026-47626 · NVIDIA DGX Spark system firmwareHigh
- NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attackerCVE-2026-24262 · NVIDIA DGX Spark system firmwareHigh
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theCVE-2026-43466 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingCVE-2026-6484 · Insyde InsydeH2O (unverified firmware volume in the boot chain)High
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theCVE-2013-3619 · Supermicro IPMI BMC firmwareHigh
- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soCVE-2014-8272 · Dell iDRAC6/iDRAC7 IPMI 1.5 session handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.