VIRTIO-BLK Vulnerability in NVIDIA SNAP-4 Container
CVE-2025-33215

6.8MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
24 March 2026

What is CVE-2025-33215?

NVIDIA SNAP-4 Container presents a vulnerability in its VIRTIO-BLK component that can be exploited by a malicious guest virtual machine. By sending specially crafted messages, the attacker could manipulate pointer offsets, leading to potential denial of service scenarios. This affects the availability of storage resources across other virtual machines, compromising overall system functionality.

Affected Version(s)

SNAP-4 Container BlueField-3 All versions prior to SNAP-4.9.1 and SNAP-4.5.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.