CVE-2025-23263

7.6

NVIDIA · DOCA-Host and Mellanox OFED

NVIDIA DOCA-Host and Mellanox OFED are vulnerable to a VGT+ feature flaw, allowing a VM-based attacker to escalate privileges and cause a denial of service on the VLAN.

Executive summary

A critical privilege escalation and denial of service vulnerability in the NVIDIA VGT+ feature allows local VM attackers to compromise host network integrity.

Vulnerability

The flaw exists in the VGT+ feature due to incorrect execution-assigned permissions (CWE-279). An attacker with low-level privileges on a virtual machine can trigger this condition to achieve privilege escalation and impact VLAN availability.

Business impact

The vulnerability carries a CVSS score of 7.6, reflecting its potential for significant impact on system integrity and availability. Successful exploitation allows unauthorized users to escalate privileges and disrupt network services, which could lead to unauthorized data access or widespread operational downtime within virtualized environments.

Remediation

Immediate Action: Update NVIDIA DOCA-Host and Mellanox OFED to the versions specified in the vendor security advisory (a_id/5654) to eliminate the vulnerable code path.

Proactive Monitoring: Monitor network infrastructure logs for unusual VLAN traffic patterns or unauthorized attempts to manipulate virtual network interfaces.

Compensating Controls: Implement strict network segmentation between virtual machines and restrict access to management interfaces to minimize the blast radius of a potential compromise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for privilege escalation within virtualized environments, administrators should prioritize updating affected NVIDIA software as soon as possible. Testing the provided patches in a staging environment is advised to ensure compatibility before deploying to production hosts.

More NVIDIA CVEs

Sources