Impact
NVIDIA Megatron Bridge for Linux contains a flaw that allows an attacker to manipulate the code generation process, classified as CWE‑94. This weakness can result in the execution of arbitrary code, enabling an attacker to gain elevated privileges, tamper with data, and disclose sensitive information. The vulnerability relies on the bridge’s ability to generate code based on supplied input, and a successful exploitation would give the attacker control over the execution environment.
Affected Systems
All installations of NVIDIA Megatron Bridge for Linux are potentially affected. The advisory does not provide specific version ranges, so any deployed instance should be considered at risk until a vendor‑supplied fix is available.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity issue and the EPSS score of <1% suggests a very low likelihood of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector can be inferred as an attacker delivering malformed or malicious input to the bridge’s code generation interface, which may be accessed from local or privileged contexts. If successfully exploited, the attacker would achieve full code execution on the system.
OpenCVE Enrichment