NVIDIA ConnectX and BlueField Command Interface Vulnerability
CVE-2025-23351

9CRITICAL

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
1 July 2026

What is CVE-2025-23351?

NVIDIA ConnectX and BlueField contain a vulnerability in their command interface, which can be exploited by a local user with virtual function (VF) access. Through carefully crafted input, this vulnerability allows for out-of-bounds writes, potentially enabling the execution of arbitrary code on the affected device. This represents a significant security risk, as it undermines the integrity of the system and could lead to unauthorized actions being executed.

Affected Version(s)

BlueField GA BlueField-2(46) All versions prior to 46.3008

BlueField LTS22 BlueField-2(35) All versions prior to 35.8002

BlueField LTS23 BlueField-2(39) All versions prior to 39.8002

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.