NVIDIA Releases Security Updates Addressing DoS, EoP, and Data Disclosure Flaws

NVIDIA has issued critical security updates addressing vulnerabilities in Bluefield, ConnectX, DOCA, Mellanox DPDK, Cumulus Linux, and NVOS.

Customers should immediately download and install the patched components from the NVIDIA Product Security portal.

Earlier evaluation versions are available upon request via NVOnline.

Summary of Addressed Vulnerabilities

The following table summarizes seven CVEs resolved in this release.

Each entry includes the CVSS v3.1 vector, base score, severity, associated CWE™ category, and potential impacts.

CVE IDProduct ComponentCVSS v3.1 VectorScoreSeverityCWE™Impact
CVE-2025-23256BlueField management interfaceAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H8.7High863Escalation of privileges, DoS, information disclosure, data tampering
CVE-2025-23257DOCA collectx-clxapidevAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H7.3High732Privilege escalation
CVE-2025-23258DOCA collectx-dpeserver (arm64)AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H7.3High732Privilege escalation
CVE-2025-23259Mellanox DPDK Poll Mode DriverAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H6.5Medium362Information disclosure, denial of service
CVE-2025-23262ConnectX management interfaceAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H6.3Medium863Escalation of privileges, DoS, information disclosure, data tampering
CVE-2025-23261Cumulus Linux & NVOS loggingAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N5.5Medium532Information disclosure (hashed passwords in logs)

Affected Versions and Updated Releases

This release also maps each CVE to the affected products, platforms/OS, and patched versions.

Administrators should verify their current deployments against this table and upgrade accordingly.

CVE IDAffected Product(s)Platform/OSAffected VersionsPatched Version
23257DOCA collectx-clxapidevLinux – Debian basedAll 2.9 < 2.9.3; all 2.102.9.3, 3.0.0
23258DOCA collectx-dpeserver (arm64)Linux – Debian arm64All 2.5 < 2.5.4; 2.9 < 2.9.3; all 2.102.5.4; 2.9.3; 3.0.0
23256BlueField GA & LTS22–24BlueField-2,3Versions prior to 35.4554 / 39.5050 / 43.3608 / 45.102035.4554; 39.5050; 43.3608; 45.1020
23262ConnectX-4/5/6/7/8 GA & LTS22–24ConnectX seriesVersions prior to 12.28.4704; 14.32.1908; 35.4554; 39.5050; 43.3608; 45.102012.28.4704; 14.32.1908; 35.4554; 39.5050; 43.3608; 45.1020
23259Mellanox DPDK 22.11/20.11/UpstreamAny20.11 < 7.8.0; 22.11 < 2504.1.0; upstream < 25.07; various LTS branches20.11.7.9.0; 22.11_2504.1.0; 23.11.5 LTS; 24.11.3 LTS; 25.07
23261Cumulus Linux; NVOSCumulus 5.x; NVOS 25.02.xxxxCumulus 5.9–5.12; NVOS 25.02.21xx–25.02.4xxxCumulus 5.13; NVOS 25.02.42xx, etc.

Download links and firmware updates are available on the NVIDIA networking portal: ConnectX-4/6/7/8 firmware, DOCA/DPDK packages, and Cumulus Linux.

For CVE-2025-23261, customers should sanitize log files to remove any exposed hashed credentials.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories