Junglewise Threat Intelligence

CVE-2026-65125: NVIDIA Infrastructure Controller for Linux path traversal

CVE-2026-65125 · Severity: medium · CVSS 6.6 · Published 2026-09-22

Technologies: Nvidia Infrastructure Controller for Linux. Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller for Linux is a system management tool that monitors and controls hardware infrastructure on Linux servers. The vulnerability allows an attacker to manipulate file paths and names, potentially leading to unauthorized code execution, privilege escalation, data modification, or service disruption. Exploitation does not require user interaction or specialized network access.

Technical details

A path traversal vulnerability in NVIDIA Infrastructure Controller for Linux permits external control of file names or paths, potentially allowing arbitrary code execution. The flaw is triggered through local or network-accessible attack vectors and may be exploited without authentication. Successful exploitation could result in privilege escalation, code execution, data tampering, or denial of service depending on the controller's privileges and the attacker's objectives.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats