Impact
NVIDIA Megatron Bridge for Linux contains an improper control of dynamically managed code resources flaw, identified as CWE-470. The vulnerability allows an attacker who can influence the dynamic code loading mechanism to execute arbitrary code, elevate privileges, tamper with data, or expose sensitive information
Affected Systems
The affected product is NVIDIA Megatron Bridge running on Linux platforms. No specific release versions were disclosed, so all publicly released versions of the product are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates medium‑to‑high severity, while the EPSS score of < 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Based on the description, it is inferred that an attacker who can trigger the dynamic code loading mechanism—potentially a local user or a remote process with sufficient permissions—could achieve code execution or privilege escalation. Because of the significant confidentiality and integrity implications, the risk to affected systems remains high.
OpenCVE Enrichment