Impact
NVIDIA Megatron Bridge for Linux contains an improper deserialization flaw that allows the software to parse untrusted data without proper validation. The weakness is classified as CWE‑502 and can lead to arbitrary code execution, privilege escalation, data tampering, and disclosure. The official CVSS score of 7.8 indicates a high severity impact, and if the exploit is successful the attacker would gain full control over the affected system.
Affected Systems
The affected product is NVIDIA Megatron Bridge for Linux. No specific version information is available in the current advisories, so all installed instances of this software are potentially vulnerable.
Risk and Exploitability
The threat level is high due to the CVSS rating, and the vulnerability is not currently listed in the CISA KEV catalog. A successful exploit requires the attacker to supply crafted serialized data to the Bridge; the attack vector is inferred to be triggered by any component that feeds input into the Bridge, which could be local or remote if the Bridge is exposed. The EPSS score of < 1% indicates a very low likelihood of exploitation, but the high severity and potential impact still necessitate timely remediation.
OpenCVE Enrichment