Impact
An out-of-bounds write (CWE-787) exists in the command interface of NVIDIA ConnectX and BlueField devices. A local user with access to a virtual function (VF) can provide crafted input that causes the device to write beyond the bounds of an internal buffer, potentially leading to arbitrary code execution. The vulnerability is rated critical with a CVSS score of 9.0, highlighting its severe impact.
Affected Systems
The affected products are NVIDIA BlueField GA, NVIDIA BlueField LTS22, LTS23, LTS24, NVIDIA ConnectX GA, LTS22, LTS23, LTS24, ConnectX-4, and ConnectX-4 LX. No specific version qualifiers are disclosed; the flaw applies to any hardware that allows VF manipulation. The vulnerability requires local user privileges that can configure or interact with a virtual function, a capability typically reserved for trusted administrators or management software.
Risk and Exploitability
The risk level remains high because local exploitation would grant an attacker full control over the device, enabling arbitrary code execution. The EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker must have the ability to send commands or configure a virtual function on the affected hardware to trigger the out-of-bounds write.
OpenCVE Enrichment