NVIDIA ConnectX and BlueField Command Interface Vulnerability
CVE-2025-23351
9CRITICAL
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 1 July 2026
What is CVE-2025-23351?
NVIDIA ConnectX and BlueField contain a vulnerability in their command interface, which can be exploited by a local user with virtual function (VF) access. Through carefully crafted input, this vulnerability allows for out-of-bounds writes, potentially enabling the execution of arbitrary code on the affected device. This represents a significant security risk, as it undermines the integrity of the system and could lead to unauthorized actions being executed.
Affected Version(s)
BlueField GA BlueField-2(46) All versions prior to 46.3008
BlueField LTS22 BlueField-2(35) All versions prior to 35.8002
BlueField LTS23 BlueField-2(39) All versions prior to 39.8002