top of page
perceptive_background_267k.jpg

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bou…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 19:17:24

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Cloud & Virtualization, Zero-Day Vulnerabilities

CVE-2025-23350 is a vulnerability affecting NVIDIA ConnectX and BlueField network adapters. The flaw resides in the command interface and allows a local user with virtual function (VF) access to trigger a write out-of-bounds condition via crafted input. Successful exploitation could lead to arbitrary code execution directly on the affected device. This presents a significant risk in virtualized and multi-tenant environments where VF access may be granted to guest or less-privileged users. The vulnerability has been assigned a high criticality rating. NVIDIA has published a security advisory through their product-security GitHub repository. The issue is currently awaiting full analysis on the NVD. Organizations using NVIDIA ConnectX or BlueField hardware in virtualized deployments should monitor for patches and mitigations.

Technical details

Mitigation steps:

Affected products:

NVIDIA ConnectX
NVIDIA BlueField

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page