Out-of-Bounds Read Vulnerability in NVIDIA DGX Spark Firmware
CVE-2026-24225

6MEDIUM

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-24225?

NVIDIA DGX Spark is susceptible to an out-of-bounds read issue within its standalone MM firmware. This vulnerability allows an attacker to read memory locations beyond the intended bounds, potentially leading to unauthorized information disclosure. Exploitation of this issue may grant access to sensitive data, emphasizing the need for users to apply necessary patches and mitigations promptly to ensure system integrity and security.

Affected Version(s)

DGX Spark UEFI 0 to 1.110.12

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.