NVIDIA GPU secure microcontroller: incorrect permissions let privileged local access modify protected memory
Impact
A secure microcontroller on the GPU assigns incorrect permissions to a critical resource, so an attacker with privileged local access can modify memory that is supposed to be off limits, leading to code execution and privilege escalation on that microcontroller. This is the component that is meant to stay trustworthy when the host does not - the layer confidential-computing and attestation stories rest on. For an operator the consequence is that a privileged compromise on the node can persist or act below the host OS, which matters most on GPUs that are recycled between tenants. NVIDIA does not state how the fix is delivered or whether it needs a firmware flash.
Who can reach it
Local attacker who already has privileged access to the host, Windows or Linux. High attack complexity.
What to do
Apply the fix for your GPU model and branch as listed in NVIDIA bulletin 2026/5861. Check the bulletin for whether this lands via the driver package or a separate firmware update, and plan the node out of service accordingly - the record does not say, so do not assume a driver-only fix.
References
Related entries
- NVIDIA Triton Inference Server: Manipulating the Python backend's shared memory region produces an out-of-bounds readCVE-2025-23333 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: A crafted request causes an out-of-bounds read in the Python backend, disclosing memoryCVE-2025-23334 · NVIDIA Triton Inference ServerMedium
- HGX / DGX B300: Authentication bypass in the hardware management interfaceCVE-2025-33242 · HGX / DGX B300Medium
- NemoClaw: SSRFCVE-2026-24231 · NemoClawMedium
- Triton Inference Server: Use-after-free in request processingCVE-2026-24266 · Triton Inference ServerMedium
- vGPU Manager: Host impact via GPU command-buffer overflowCVE-2026-24201 · vGPU ManagerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.