CVE-2026-65115
6.5NVIDIA · Infrastructure Controller
NVIDIA Infrastructure Controller for Linux is susceptible to uncontrolled resource consumption, which can be triggered by an authenticated attacker to cause a denial of service condition.
Executive summary
An authenticated attacker can trigger a denial of service in the NVIDIA Infrastructure Controller for Linux by exploiting an uncontrolled resource consumption vulnerability.
Vulnerability
The vulnerability is identified as CWE-400 (Uncontrolled Resource Consumption). It allows a low-privileged authenticated user to exhaust system resources via network requests, resulting in a denial of service.
Business impact
Successful exploitation results in the unavailability of the Infrastructure Controller, which may disrupt dependent services and operational workflows. While the CVSS score of 6.5 reflects a medium severity due to the requirement for authentication, the potential for service disruption poses a significant risk to system stability and uptime for environments relying on this controller.
Remediation
Immediate Action: Update the NVIDIA Infrastructure Controller to the latest version provided by the vendor to resolve the resource management flaw.
Proactive Monitoring: Monitor system resource utilization, specifically CPU and memory usage patterns, for spikes that correlate with unauthorized or abnormal network traffic.
Compensating Controls: Implement rate limiting on the network interface and enforce strict access controls to minimize the number of users capable of interacting with the vulnerable controller.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing the NVIDIA Infrastructure Controller should prioritize updating to the latest secure version. Given that the vulnerability allows for denial of service, administrators must ensure that environment access controls are strictly enforced until the patch is successfully applied across all production instances.
More NVIDIA CVEs all →
History
- Analyst report written