GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code execution

CVSS 9.8CVE-2026-76501Firmware, BMC & network fabriccurated

Impact

With both NGOAM and SRv6 enabled, an unauthenticated attacker who can send crafted IP packets to an IP interface on the switch gets arbitrary code execution as root, or can crash the process and trigger a reload. This is the SRv6 OAM path rather than the VXLAN one ([[CVE-2026-76485]]) and needs SRv6 configured, so it hits fabrics that use segment routing over IPv6 for the datacenter underlay. Root on a leaf or spine in a GPU fabric means an attacker sits in the path of tenant traffic; a reload stalls every collective crossing that switch.

Who can reach it

Anyone who can reach an IP interface on the switch over the network, unauthenticated. Requires the NGOAM and SRv6 features to both be enabled.

What to do

Upgrade to a fixed NX-OS release listed in the Cisco advisory, which requires reloading the switch and therefore a maintenance window per device. Disabling NGOAM, or SRv6 where it is not needed, removes the exposure in the meantime. The record names no fixed version - take it from the advisory.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.