Junglewise Threat Intelligence

CVE-2025-23351: NVIDIA ConnectX and BlueField out-of-bounds write in command interface

CVE-2025-23351 · Severity: critical · CVSS 9 · Published 2026-07-01

Vendors: Nvidia.

Executive brief

NVIDIA ConnectX and BlueField networking adapters contain a vulnerability in their command interface. A local user with access to a virtual function can send specially crafted input to trigger a memory error on the device. If successfully exploited, this could allow an attacker to take full control of the networking hardware, potentially leading to data theft or service disruption.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the command interface of NVIDIA ConnectX and BlueField firmware. The flaw is triggered when a local user with Virtual Function (VF) access provides crafted input to the device's command interface. This memory corruption occurs at the firmware level and can lead to arbitrary code execution on the network adapter or DPU. The vulnerability is rated critical with a CVSS score of 9.0, as it allows for a scope jump from a virtualized environment to the hardware controller. Patches have been released across various GA and LTS firmware branches, including versions 46.3008, 35.8002, 39.8002, and 43.8002.

Affected products

  • NVIDIA BlueField GA All versions prior to 46.3008
  • NVIDIA BlueField LTS22 All versions prior to 35.8002
  • NVIDIA BlueField LTS23 All versions prior to 39.8002
  • NVIDIA BlueField LTS24 All versions prior to 43.8002
  • NVIDIA ConnectX GA All versions prior to 46.3008
  • NVIDIA ConnectX LTS22 All versions prior to 35.8002
  • NVIDIA ConnectX LTS23 All versions prior to 39.8002
  • NVIDIA ConnectX LTS24 All versions prior to 43.8002
  • NVIDIA ConnectX-4 All versions prior to 28.4702

Timeline

  • 2026-07-01: advisory: NVIDIA published security bulletin 5699

References