Impact
NVIDIA Megatron Bridge for Linux contains a flaw that allows an attacker to deserialize untrusted serialized data. Because the deserialization process is performed without validation, a crafted payload can lead to arbitrary code execution with the privileges of the Megatron Bridge process. This vulnerability corresponds to CWE‑94, Improper Neutralization of Code during Deserialization, and thus can also result in privilege escalation, data tampering, or information disclosure.
Affected Systems
All installations of NVIDIA Megatron Bridge for Linux are potentially affected. No specific version information is provided, so any instance of the product should be treated as vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, while the EPSS score of < 1% denotes a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, so it is not known to be actively exploited. The likely attack vector is any interface that accepts serialized input and performs unrestricted deserialization; an attacker could target the bridge through remote connections or compromised data streams.
OpenCVE Enrichment