CVE-2026-65125
6.6NVIDIA · Infrastructure Controller
NVIDIA Infrastructure Controller for Linux is vulnerable to external control of a file name or path, potentially allowing code execution and privilege escalation by a highly privileged attacker.
Executive summary
A vulnerability in the NVIDIA Infrastructure Controller for Linux could allow a high-privileged attacker to achieve remote code execution, data tampering, or denial of service.
Vulnerability
The software is susceptible to CWE-73, which involves external control of a file name or path. This vulnerability requires high privileges (PR:H) to exploit, meaning an attacker must already have significant administrative access to the system to trigger the flaw.
Business impact
While the CVSS score of 6.6 is categorized as Medium, the potential for code execution and privilege escalation poses a significant risk to organizational integrity. Successful exploitation could allow an attacker to bypass security controls, modify sensitive system data, or render critical infrastructure services unavailable, leading to severe operational disruption and potential loss of data confidentiality.
Remediation
Immediate Action: Update the NVIDIA Infrastructure Controller to the latest available version provided by the vendor. Consult the official NVIDIA product security portal for specific patch details and upgrade paths.
Proactive Monitoring: Review system access logs for unusual file system activity or unauthorized attempts to access or modify sensitive paths. Monitor for anomalous behavior in the Infrastructure Controller process.
Compensating Controls: Implement strict access control lists (ACLs) to limit the privileges of accounts that interact with the Infrastructure Controller. Utilize host-based intrusion detection systems to alert on suspicious process execution patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise, organizations should prioritize the transition to a patched version of the NVIDIA Infrastructure Controller. Administrators must ensure that the update is applied during the next maintenance window to prevent the risk of privilege escalation or unauthorized file manipulation.
More NVIDIA CVEs all →
History
- Analyst report written