Junglewise Threat Intelligence

CVE-2026-65127: NVIDIA Infrastructure Controller for Linux information disclosure in debug logs

CVE-2026-65127 · Severity: medium · CVSS 4.1 · Published 2026-09-22

Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller is a system management component for Linux servers. The product fails to clear debug information from memory and logs, allowing an attacker to read sensitive system details without special privileges. This information exposure could facilitate further attacks on the infrastructure.

Technical details

The vulnerability stems from uncleared debug information in NVIDIA Infrastructure Controller for Linux, leading to information disclosure. An attacker can access sensitive system details by reading accessible debug data without requiring authentication or elevated privileges. A fix is available from NVIDIA.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats