Description
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
Published: 2026-07-01
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a write‑outside‑bounds condition in the command interface of NVIDIA ConnectX and BlueField devices. A local user who has virtual function (VF) access can supply crafted input that causes the device to write beyond the bounds of a buffer. If successfully exploited, the attacker can achieve arbitrary code execution on the device, compromising confidentiality, integrity, or availability of the host system.

Affected Systems

The affected products are NVIDIA's BlueField family – the general‑availability (GA) version and the LTS22, LTS23, LTS24 releases – as well as the ConnectX family – GA and LTS22‑LTS24. Specific firmware or driver versions within those product lines are impacted, but detailed version data is not listed here.

Risk and Exploitability

The CVSS score of 9 indicates a high‑severity flaw. The EPSS score is not reported, making it unclear how frequently the vulnerability is exploited in the wild, and it is not currently listed in the CISA KEV catalog. The likely attack vector is local, requiring that the attacker has VF privileges on the device. Once this condition is met, the out‑of‑bounds write can be leveraged to execute arbitrary instructions and take control of the device, potentially affecting the host OS running on the NIC or host system.

Generated by OpenCVE AI on July 1, 2026 at 18:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA firmware or driver update that addresses this vulnerability once released by NVIDIA.
  • Restrict virtual function access on the device to only trusted hosts and applications, disabling VF for untrusted workloads.
  • If an update is not yet available, isolate the device from untrusted networks and monitor for anomalous activity; consider using a jump host or dedicated VF to reduce exposure.

Generated by OpenCVE AI on July 1, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Write‑Outside‑Bounds Vulnerability in NVIDIA ConnectX and BlueField Command Interface Leading to Arbitrary Code Execution

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-01T16:03:30.696Z

Reserved: 2025-01-14T01:07:21.737Z

Link: CVE-2025-23350

cve-icon Vulnrichment

Updated: 2026-07-01T16:03:27.311Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T18:30:15Z

Weaknesses