NVIDIA BlueField DPU Vulnerability Could Lead to Denial of Service, Data Tampering, and Limited Information Disclosure
CVE-2024-0106
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 1 November 2024
What is CVE-2024-0106?
The NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability related to improper privilege handling. This issue could allow attackers to exploit the system, resulting in disruptions such as denial of service, potential data tampering, and limited information disclosure. Addressing this security risk is crucial for maintaining the integrity and availability of systems utilizing NVIDIA technology.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BlueField 1 All versions prior to 18.31.1014
BlueField GA BlueField 2 All versions prior to xx.41.1000
BlueField LTS22 BlueField 2 All versions prior to xx.35.4030
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved