Database/Firmware, BMC & network fabric
NVIDIA DGX Spark firmware: second out-of-bounds write reachable by a privileged local attacker
Impact
A second out-of-bounds write in DGX Spark system firmware, disclosed alongside CVE-2026-24262 in the same bulletin and with the same scoring. A privileged local attacker gets a write outside the intended buffer in firmware context, with a changed scope and full confidentiality, integrity and availability impact. As with the companion issue, code planted at this level persists across OS reinstalls, so a suspected compromise is only resolved by reflashing. Track it separately only for inventory purposes; operationally it is the same maintenance window.
Who can reach it
Local attacker already holding high privileges on the DGX Spark host (CVSS AV:L/PR:H). No network path, no user interaction.
What to do
Take the fixed firmware version from NVIDIA product-security bulletin 5867; the CVE record does not state one. Flash DGX Spark system firmware with the machine out of service - the same update also addresses CVE-2026-24262 and CVE-2026-24263.
References
Related entries
- NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attackerCVE-2026-24262 · NVIDIA DGX Spark system firmwareHigh
- NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attackerCVE-2026-24263 · NVIDIA DGX Spark system firmwareHigh
- Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingCVE-2026-6484 · Insyde InsydeH2O (unverified firmware volume in the boot chain)High
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theCVE-2013-3619 · Supermicro IPMI BMC firmwareHigh
- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soCVE-2014-8272 · Dell iDRAC6/iDRAC7 IPMI 1.5 session handlingHigh
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.