Impact
NVIDIA Megatron Bridge for Linux contains a deserialization vulnerability (CWE-502) that allows the processing of untrusted data. A successful exploit can trigger arbitrary code execution, enabling an attacker to gain higher privileges, tamper with data, or disclose sensitive information.
Affected Systems
The vulnerability affects NVIDIA Megatron Bridge for Linux. Specific affected versions are not disclosed in the available data, so all deployments are potentially exposed.
Risk and Exploitability
The CVSS score of 7.8 signifies high severity potential. The EPSS score of < 1% indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves the receipt of malicious data by the bridge service, suggesting that network or local access to the service could be required. The overall risk is moderate to high until a fix is applied.
OpenCVE Enrichment