Impact
NVIDIA OpenShell for Linux includes a flaw in its sandbox provisioning API that allows an attacker to supply incomplete lists of disallowed inputs. This bypass can let unauthorized code run within the sandbox, resulting in full code execution and privilege escalation. The vulnerability also poses risks of data disclosure, tampering, and service disruption.
Affected Systems
The affected product is NVIDIA OpenShell for Linux. No specific version numbers are provided in the CVE data, indicating that all versions may be susceptible until the vendor issues a fix. Administrators should determine if the affected OpenShell installation is present.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical impact, and the EPSS score is not available, but the lack of a KEV listing suggests no actively exploited public exploits have been reported yet. Nevertheless, an attacker with access to the sandbox provisioning interface—likely a local user or compromised application—could exploit the flaw, resulting in complete compromise. The severity and potential for privilege escalation warrant immediate attention once a vendor patch or mitigation is applied.
OpenCVE Enrichment