


Perceptive Security
SOC/SIEM Consultancy

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bou…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 19:17:24
Source:
nvd.nist.gov
Network Infrastructure, Cloud & Virtualization, Zero-Day Vulnerabilities
CVE-2025-23350 is a vulnerability affecting NVIDIA ConnectX and BlueField network adapters. The flaw resides in the command interface and allows a local user with virtual function (VF) access to trigger a write out-of-bounds condition via crafted input. Successful exploitation could lead to arbitrary code execution directly on the affected device. This presents a significant risk in virtualized and multi-tenant environments where VF access may be granted to guest or less-privileged users. The vulnerability has been assigned a high criticality rating. NVIDIA has published a security advisory through their product-security GitHub repository. The issue is currently awaiting full analysis on the NVD. Organizations using NVIDIA ConnectX or BlueField hardware in virtualized deployments should monitor for patches and mitigations.
Technical details
Mitigation steps:
Affected products:
NVIDIA ConnectX
NVIDIA BlueField
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-23350
https://github.com/NVIDIA/product-security/tree/main/2026/5699
https://www.cve.org/CVERecord?id=CVE-2025-23350
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
