CVE-2025-23350Disclosure

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - NVIDIA ConnectX/BlueField VF command interface out-of-bounds write (CVE-2025-23350) NVIDIA ConnectX and BlueField devices are affected by a flaw in the device command interface reachable from a Virtual Function (VF) context. The root cause is an out-of-bounds write triggered by improper bounds checking on crafted command input. An attacker who already has local access with VF privileges (e.g., a tenant VM/container assigned a VF via SR-IOV) can send maliciously formed commands to corrupt device memory. If exploited, this can lead to arbitrary code execution on the NIC/DPU, enabling device compromise, potential cross-tenant impact, and disruption of network/storage offload operations. 👉 Affected: NVIDIA ConnectX and BlueField (VF command interface; versions not specified) | No fix yet - treat as suspicious

    Post summary

    The post discloses CVE‑2025‑23350, explaining an out‑of‑bounds write in NVIDIA ConnectX/BlueField devices that could lead to arbitrary code execution, but offers no PoC, exploit, or remediation details.

    0000066
    232 followersView on X

Explore more