Impact
NVIDIA Megatron Bridge for Linux has a vulnerability that allows an attacker to supply untrusted serialized data, which the bridge blindly deserializes. By crafting malicious input streams, an attacker can trigger harmful code execution, elevate privileges, tamper with data, or disclose sensitive information. The flaw is classified as CWE‑502, indicating unsafe handling of serialized data leading to potential execution of arbitrary logic. Based on the description, this attack likely occurs when the bridge receives malformed input from a local or remote source.
Affected Systems
All instances of NVIDIA Megatron Bridge for Linux are affected. The vendor release information does not specify fixed versions; this lack of detail is inferred from the description. Until NVIDIA publishes a patch, any current installation should be considered at risk. The missing fixed-version details are inferred from the description.
Risk and Exploitability
The CVSS score of 7.8 signals a high potential impact, while an EPSS score of <1% indicates a very low likelihood of exploitation as of the current data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred from the description to be an attacker transmitting crafted serialized input to the bridge, which could occur locally or remotely depending on the bridge's exposure to untrusted networks. Limiting input sources or disabling the bridge would mitigate the risk until a vendor fix is applied.
OpenCVE Enrichment