Executive brief
NVIDIA DGX Spark is a high-performance data processing system used for enterprise AI and machine learning workloads. A firmware vulnerability allows a privileged attacker to cause a NULL pointer dereference, potentially leading to system crashes, unauthorized code execution, or data tampering. This could compromise the integrity and availability of critical data processing operations.
Technical details
A NULL pointer dereference vulnerability exists in the NVIDIA DGX Spark system firmware, requiring privileged attacker access to exploit. The vulnerability can be triggered to cause code execution, privilege escalation, denial of service, information disclosure, and data tampering. Attack requires elevated privileges and direct or local access to the system firmware layer. A patch is expected from NVIDIA as part of their regular security bulletin program.
Affected products
- NVIDIA DGX Spark <UNKNOWN>
Timeline
- 2026-08-25: disclosed