NVIDIA BlueField - VIRTIO-Net emulation: A VM user sends a crafted message to the BlueField VIRTIO-Net device and gets
Impact
A VM user sends a crafted message to the BlueField VIRTIO-Net device and gets a write-what-where primitive, reaching code execution in the VIRTIO-Net context on the DPU. The DPU is the component you offloaded tenant network isolation onto - a tenant VM reaching code execution inside it inverts the trust model of the whole design. Scored 9.0 with a changed scope.
Who can reach it
A user inside a tenant VM talking to the emulated virtio-net device its own hypervisor exposed. No host or DPU credentials needed. This is the guest-to-DPU boundary.
What to do
Update the BlueField VIRTIO-Net firmware/software per bulletin 5815 across GA, LTS23, LTS24 and LTS25 branches as applicable. Cost: a DPU firmware update takes the DPU's dataplane down, which means the host loses network - treat it as a full node drain, not a live update. Sequence carefully: a half-updated DPU fleet has inconsistent offload behaviour.
References
Related entries
- ConnectX / BlueField firmware: Improper certificate validationCVE-2024-0105 · ConnectX / BlueField firmwareHigh
- NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device node: The GPU-side twin ofCVE-2012-0946 · NVIDIA UNIX (Linux/FreeBSD/Solaris) GPU driver before 295.40 - /dev/nvidia* device nodeHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Any local account on a Windows GPU host can call the driver's escapeCVE-2018-6247 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel read/write from an unprivileged escape callCVE-2018-6248 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): NULL dereference in the kernel-mode layer reachableCVE-2018-6249 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Same class as the other early-2018 escape bugs: an unprivilegedCVE-2018-6250 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.