Impact
The NVIDIA Megatron Bridge for Linux contains a flaw where the system does not properly validate certain inputs. This improper input handling can lead to arbitrary code execution, privilege escalation, data tampering, and information disclosure. The weakness is classified as a data handling vulnerability (CWE-502).
Affected Systems
NVIDIA Megatron Bridge for Linux is affected. No specific version details are supplied by the CNA, so the risk applies to all released variants until a vendor fix is issued.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, while the EPSS score of < 1% suggests a low current probability of exploitation. It is not listed in CISA’s KEV catalog. The likely attack vector is inferred from the description; the bridge’s communication interface likely exposes an entry point that may be reachable from local or remote hosts depending on network exposure. Because the flaw can be triggered through input supplied over that interface, an attacker could achieve code execution and privilege escalation, warranting prompt patching.
OpenCVE Enrichment