
🚨 CRITICAL - NVIDIA ConnectX/BlueField VF command interface out-of-bounds write (CVE-2025-23350) NVIDIA ConnectX and BlueField devices are affected by a flaw in the device command interface reachable from a Virtual Function (VF) context. The root cause is an out-of-bounds write triggered by improper bounds checking on crafted command input. An attacker who already has local access with VF privileges (e.g., a tenant VM/container assigned a VF via SR-IOV) can send maliciously formed commands to corrupt device memory. If exploited, this can lead to arbitrary code execution on the NIC/DPU, enabling device compromise, potential cross-tenant impact, and disruption of network/storage offload operations. 👉 Affected: NVIDIA ConnectX and BlueField (VF command interface; versions not specified) | No fix yet - treat as suspicious
Post summary
The post discloses CVE‑2025‑23350, explaining an out‑of‑bounds write in NVIDIA ConnectX/BlueField devices that could lead to arbitrary code execution, but offers no PoC, exploit, or remediation details.
