Buffer Size Miscalculation in NVIDIA SNAP-4 Container Configuration Interface
CVE-2025-33216

6.8MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
24 March 2026

What is CVE-2025-33216?

The NVIDIA SNAP-4 Container has a vulnerability within its configuration interface that allows an attacker operating from a virtual machine (VM) to manipulate the buffer size through specially crafted configurations. This miscalculation can cause the SNAP service to crash, resulting in denial of service for the storage service on the host system. Exploitation of this flaw could disrupt service availability and compromise system integrity.

Affected Version(s)

SNAP-4 Container BlueField-3 All versions prior to SNAP-4.9.0 and SNAP-4.5.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.