Executive brief
NVIDIA DGX Spark is a high-performance AI computing system used for machine learning and data center workloads. A vulnerability in its system firmware could allow a privileged attacker to corrupt memory, potentially leading to unauthorized code execution, system crashes, or data tampering. This poses a significant risk to organizations relying on DGX Spark for mission-critical AI infrastructure.
Technical details
The vulnerability is an out-of-bounds write flaw in NVIDIA DGX Spark's system firmware. It requires an attacker with elevated privileges to exploit. A successful exploit can lead to code execution, privilege escalation, denial of service, information disclosure, and data tampering. The vulnerability affects the firmware component directly, making it a low-level system issue. Patches are expected from NVIDIA as part of their security update cycle.
Affected products
- NVIDIA DGX Spark <UNKNOWN>
Timeline
- 2026-08-25: disclosed
- other: Not reported as exploited in the wild as of publication date