Junglewise Threat Intelligence

CVE-2026-65083: NVIDIA OpenShell for Linux incomplete input allowlist in sandbox provisioning API

CVE-2026-65083 · Severity: critical · CVSS 9.9 · Published 2026-08-25

Technologies: Linux Kernel, Nvidia OpenShell for Linux. Vendors: Linux, Nvidia.

Executive brief

NVIDIA OpenShell for Linux is a system utility for Linux environments that manages sandboxed execution environments. A flaw in its sandbox provisioning API allows attackers to bypass security controls by providing inputs that were not properly validated against the allowlist, potentially leading to unauthorized code execution, privilege escalation, and data compromise on affected systems.

Technical details

The vulnerability exists in the sandbox provisioning API of NVIDIA OpenShell for Linux, where an incomplete allowlist of disallowed inputs permits an attacker to supply malicious or unexpected values that circumvent input validation controls. This input validation weakness is network-accessible and can be exploited without requiring prior authentication or special privileges. A successful exploit enables code execution at elevated privilege levels, information disclosure, tampering with system data, and denial of service. NVIDIA has issued a fix; affected users should upgrade to the patched version immediately.

Affected products

  • NVIDIA OpenShell for Linux <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats