NVIDIA Patches Vulnerabilities Causing DoS, EoP, and Data Exposure
NVIDIA has released critical security updates for several of its products, including BlueField, ConnectX, DOCA, Mellanox DPDK, Cumulus Linux, and NVOS. These updates address vulnerabilities that could potentially lead to denial of service (DoS),…
NVIDIA has released critical security updates for several of its products, including BlueField, ConnectX, DOCA, Mellanox DPDK, Cumulus Linux, and NVOS. These updates address vulnerabilities that could potentially lead to denial of service (DoS), escalation of privileges (EoP), and information disclosure.
Users are advised to download and install the updates immediately to ensure system protection. Updates can be accessed through the NVIDIA Product Security portal . Evaluation version users should contact their account manager for NVOnline access.
CVE ID CVSS v3.1 Score Severity Impacts
CVE-2025-23256 8.7 High EoP, DoS, disclosure, data tampering
CVE-2025-23257 7.3 High EoP
NVIDIA has released critical security updates for several of its products, including BlueField, ConnectX, DOCA, Mellanox DPDK, Cumulus Linux, and NVOS.
CVE-2025-23258 7.3 High EoP
CVE-2025-23259 6.5 Medium Disclosure, DoS
CVE-2025-23262 6.3 Medium EoP, DoS, disclosure, data tampering
CVE-2025-23261 5.5 Medium Information disclosure
BlueField: All versions prior to 45.1020 (GA) and corresponding LTS releases. Updated to 45.1020 (GA), 35.4554, 39.5050, or 43.3608 depending on branch. DOCA: Debian-based collectx-clxapidev and collectx-dpeserver packages updated to 2.9.3, 2.5.4, and 3.0.0. Mellanox DPDK: Versions prior to 22.11_2504.1.0, 22.11_2410.4.0 LTS, 22.11_2310.6.0 LTS, and various upstream releases. Updated to 25.07 and corresponding LTS builds. ConnectX: GA and LTS versions updated to 45.1020, 35.4554, 39.5050, 43.3608; ConnectX-4 updates planned by end of September. Cumulus Linux & NVOS: NVOS branches 25.02.xx updated to 25.02.42xx; Cumulus Linux updated to 5.13, 5.11.1.1009, 5.9.2.0020, and related builds.
Update Immediately: Install the latest firmware and software versions listed above. Review Logs: For CVE-2025-23261, sanitize and remove any exposed passwords from existing logs. Access Control: Limit local access to management interfaces on BlueField and ConnectX devices. Contact Support: For early access or assistance, reach out to your NVIDIA account manager.
Applying these updates will help organizations protect crucial networking components from service disruptions, privilege breaches, and data leaks.
Based on reporting by GBHackers.
