Impact
NVIDIA Megatron Bridge for Linux contains an unsafe deserialization flaw (CWE-502) that permits an attacker to provide crafted data to the bridge service and trigger arbitrary code execution. Successful exploitation could grant the attacker elevated privileges, enable data tampering, and allow sensitive information to be disclosed, thus compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
NVIDIA Megatron Bridge for Linux is the only product identified as affected. No version constraints are listed, so all current releases of the bridge are considered vulnerable until an official fix is released by NVIDIA.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating high severity, while the EPSS score of < 1% suggests a low probability of exploitation at present. It is not included in CISA’s KEV catalog. Attackers would likely need to deliver a malicious serialized payload over the network if the bridge service is exposed to untrusted hosts, or locally via a user already present on the system. The risk is amplified by the potential for remote code execution coupled with privilege escalation.
OpenCVE Enrichment