NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NVIDIA | BlueField LTS22 | All versions prior to 35.8002CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS23 | All versions prior to 39.8002CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS24 | All versions prior to 43.8002CNA affecteddefault unaffected | |
| NVIDIA | BlueField GA | All versions prior to 46.3008CNA affecteddefault unaffected | |
| NVIDIA | ConnectX LTS22 | All versions prior to 35.8002CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.3 Bluesky, 0.4 Mastodon, and 2.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.9 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.