GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA DGX Spark firmware: second out-of-bounds write reachable by a privileged local attacker

CVE-2026-47626Firmware, BMC & network fabriccurated

Impact

A second out-of-bounds write in DGX Spark system firmware, disclosed alongside CVE-2026-24262 in the same bulletin and with the same scoring. A privileged local attacker gets a write outside the intended buffer in firmware context, with a changed scope and full confidentiality, integrity and availability impact. As with the companion issue, code planted at this level persists across OS reinstalls, so a suspected compromise is only resolved by reflashing. Track it separately only for inventory purposes; operationally it is the same maintenance window.

Who can reach it

Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.

What to do

Take the fixed firmware version from NVIDIA product-security bulletin 5867; the CVE record does not state one. Flash DGX Spark system firmware with the machine out of service - the same update also addresses CVE-2026-24262 and CVE-2026-24263.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.