Impact
NVIDIA Megatron Bridge for Linux contains a flaw where dynamic code resources can be improperly controlled. This weakness, categorized as CWE‑502, can allow an attacker to execute arbitrary code, gain higher privileges, alter data, and expose sensitive information if successfully exploited.
Affected Systems
The affected component is NVIDIA Megatron Bridge for Linux. No version specifics are listed in the current advisory, meaning all installations of this product should be evaluated for patches or mitigations. Administrators should review their deployment for any active instances of Megatron Bridge.
Risk and Exploitability
The CVSS score of 7.8 marks the issue as high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not present in the CISA KEV catalog. The attack vector is not explicitly provided; it is inferred that an attacker would need local interaction with the system or access to a publicly exposed interface that manages dynamic code resources. Despite the low exploitation probability, the potential for code execution and privilege escalation makes this vulnerability a significant risk if not mitigated.
OpenCVE Enrichment