PatchSiren

NVIDIA CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65179

CVE-2026-65179 is a high-severity vulnerability in the NVIDIA NeMo Speech product, specifically in the TabularTokenizer class. The vulnerability allows for deserialization of untrusted .pkl files via pickle.load() without validation, potentially leading to code execution, data tampering, denial of service, and information disclosure. Affected systems should be identified and patched, and additional securi [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65178

CVE-2026-65178 is a high-severity vulnerability in NVIDIA NeMo's dataset-loading workflow. A maliciously crafted model_config.yaml can inject unsafe parameters, potentially leading to code execution, data tampering, denial of service, and information disclosure. Defenders should assess exposure, prioritize remediation, and verify affected versions and vendor-provided patches.

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65130

CVE-2026-65130 is a high-severity vulnerability in NVIDIA Infrastructure Controller for Linux that could allow an attacker to cause OS command injection, potentially leading to code execution, data tampering, denial of service, and information disclosure. The vulnerability has a CVSS score of 8 and is considered HIGH severity. Defenders should verify exposure and assess potential impact, focusing on syste [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65129

The vulnerability in NVIDIA Infrastructure Controller for Linux, tracked as CVE-2026-65129, allows an attacker to cause improper certificate validation. This could lead to potential information disclosure, data tampering, and denial of service. Linux infrastructure administrators and security teams should assess exposure and take necessary actions. The CVE record and NVD entry provide details on the vulne [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65128

The CVE-2026-65128 vulnerability is a SQL injection issue in NVIDIA Infrastructure Controller for Linux. This high-severity vulnerability could lead to code execution, data tampering, denial of service, and information disclosure if exploited. Linux infrastructure administrators and security teams should assess exposure and prioritize patching and mitigation efforts. However, specific version information [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65127

CVE-2026-65127 is a vulnerability in NVIDIA Infrastructure Controller for Linux that could lead to exposure of sensitive system information due to uncleared debug information. Defenders should assess exposure, prioritize remediation, and verify system information disclosure risks. The vulnerability has a CVSS score of 4.1 and is classified as CWE-1258. Affected Linux systems using NVIDIA Infrastructure Co [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65126

CVE-2026-65126 debrief based on the supplied source corpus. The vulnerability in NVIDIA Infrastructure Controller for Linux could lead to improper enforcement of a behavioral workflow, potentially causing data tampering, denial of service, and information disclosure. Linux system administrators and security teams should assess exposure and verify patch status for NVIDIA Infrastructure Controller for Linux [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65125

CVE-2026-65125: NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. The vulnerability exists in the NVIDIA Infrastructure Controller for Linux, allowing an attacker to control file na [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65124

CVE-2026-65124 debrief based on the supplied source corpus. The vulnerability is an XML injection in NVIDIA Infrastructure Controller for Linux, which could lead to data tampering and denial of service. Defenders should verify exposure, assess potential impact, and monitor for patches or updates from NVIDIA. This involves reviewing system configurations and versions, assessing potential impact on data tam [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65118

The NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation, potentially leading to information disclosure, data tampering, and denial of service. This debrief provides an executive overview of the affected product, vulnerability class, and likely operational impact based on the CVE record and source-provided information. Linux infr [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65117

CVE-2026-65117 is a vulnerability in NVIDIA Infrastructure Controller for Linux that contains a hard-coded password. An attacker could exploit this vulnerability to cause data tampering, denial of service, and information disclosure. The vulnerability exists in NVIDIA Infrastructure Controller for Linux and allows an attacker to cause data tampering, denial of service, and information disclosure due to a [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65115

CVE-2026-65115 is a vulnerability in NVIDIA Infrastructure Controller for Linux that may cause uncontrolled resource consumption, leading to denial of service. The CVE record was published on 2026-09-22T15:17:11.777Z and was last modified on 2026-09-29T18:35:29.223Z. The NVD entry is currently Analyzed. This vulnerability affects Linux environments using NVIDIA Infrastructure Controller, and defenders sho [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65114

CVE-2026-65114 is a high-severity vulnerability in NVIDIA Infrastructure Controller for Linux, allowing for missing authentication for a critical function. This could lead to data tampering, denial of service, and information disclosure if exploited. The vulnerability exists in the NVIDIA Infrastructure Controller for Linux, where an attacker could cause missing authentication for a critical function. A s [truncated]

CRITICAL NVIDIA CVE published 2026-09-22

CVE-2026-65113

CVE-2026-65113 is a critical vulnerability in NVIDIA Infrastructure Controller for Linux, allowing potential escalation of privileges, data tampering, denial of service, and information disclosure through the use of hard-coded credentials. This vulnerability exists in the NVIDIA Infrastructure Controller for Linux, where an attacker could exploit hard-coded credentials. The vulnerability has a critical CV [truncated]

MEDIUM NVIDIA CVE published 2026-09-22

CVE-2026-65112

CVE-2026-65112 is a vulnerability in NVIDIA Infrastructure Controller for Linux that could lead to denial of service via uncontrolled resource consumption. The CVE record was published on 2026-09-22T15:17:11.390Z and was last modified on 2026-09-29T18:36:54.900Z. The NVD entry is currently Analyzed. This vulnerability affects Linux environments using NVIDIA Infrastructure Controller, and defenders should [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-65111

A code injection vulnerability exists in NVIDIA NeMo Speech for all platforms. Malicious input created by an attacker could cause code injection, potentially leading to code execution, information disclosure, and data tampering. This vulnerability has a high CVSS score, indicating a significant threat to systems and deployments using NVIDIA NeMo Speech. Defenders should assess exposure and potential impac [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-24267

NVIDIA NeMo Speech vulnerability allows remote code execution via malicious speech data. Defenders should assess exposure, prioritize remediation, and verify code execution risk. The vulnerability affects the speech data explorer component, and malicious data created by an attacker could cause remote code execution. A successful exploit might lead to code execution, escalation of privileges, information d [truncated]

HIGH NVIDIA CVE published 2026-09-22

CVE-2026-24239

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Defenders should prioritize verifying exposure and assessing potential impa [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-65099

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:29.817Z and has not been modified since then. NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. This could lead to code execution, data tampering, information disclosure, and denial of service. Organizations [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-65097

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:29.560Z and has not been modified since then. This vulnerability affects NVIDIA NemoClaw for Linux, specifically in its installation scripts, which could allow an attacker to download code without integrity checks. This could lead to code execution, escalation of privileges, information dis [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-65092

The CVE-2026-65092 vulnerability in NVIDIA OpenShell Sandbox for Linux allows an attacker to bypass L7 REST network policy, potentially leading to information disclosure and data tampering. This vulnerability has a CVSS score of 8.5 and is classified as high severity. Organizations using NVIDIA OpenShell Sandbox for Linux should be aware of this vulnerability and take steps to mitigate it. The CVE record [truncated]

MEDIUM NVIDIA CVE published 2026-08-25

CVE-2026-65088

NVIDIA NemoClaw, a component used in various NVIDIA products, contains a vulnerability where an attacker could cause invocation of a process using visible sensitive information. This vulnerability might lead to information disclosure, potentially impacting organizations relying on NemoClaw for sensitive information processing. The CVE record was published on 2026-08-25T21:17:28.680Z and has not been modif [truncated]

MEDIUM NVIDIA CVE published 2026-08-25

CVE-2026-65087

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:28.553Z and has not been modified since then. NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials, potentially leading to information disclosure and data tampering. This vulnerability has a CVSS score of 5.6 and is classified as MEDIUM [truncated]

MEDIUM NVIDIA CVE published 2026-08-25

CVE-2026-65086

The CVE-2026-65086 vulnerability in NVIDIA OpenShell for Linux is caused by a weakness in its sandbox exec handler, allowing for OS command injection. This could lead to code execution, information disclosure, and data tampering. The vulnerability has a CVSS score of 6.8 and is classified as medium severity. System administrators and security teams should be aware of this vulnerability and take necessary [truncated]

MEDIUM NVIDIA CVE published 2026-08-25

CVE-2026-65085

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:28.307Z and has not been modified since then. The vulnerability in NVIDIA OpenShell for Linux could lead to information disclosure and data tampering due to improper encoding or escaping of output. Organizations should prioritize patching and review system configurations to mitigate potenti [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-65084

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, allowing for improper certificate validation. This could lead to information disclosure, data tampering, code execution, and escalation of privileges. The vulnerability is tracked under CVE-2026-65084 and has been assessed as HIGH severity with a CVSS score of 8.1. Affected systems may require immediate attention to ensure prope [truncated]

CRITICAL NVIDIA CVE published 2026-08-25

CVE-2026-65083

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:28.050Z and has not been modified since then. The NVD entry is currently Analyzed. NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lea [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-47626

A high-severity vulnerability exists in NVIDIA DGX Spark's system firmware, potentially allowing a privileged attacker to cause an out-of-bounds write. This could lead to various consequences, including code execution and denial of service. The vulnerability is tracked as CVE-2026-47626 and has a CVSS score of 8.2. Defenders should assess their exposure and potential impact. System administrators and secu [truncated]

MEDIUM NVIDIA CVE published 2026-08-25

CVE-2026-47624

CVE-2026-47624: NVIDIA DGX Spark UEFI vulnerability allows local user to bypass administrator password protection. This Medium-severity vulnerability, tracked as CVE-2026-47624, affects NVIDIA DGX Spark systems and allows a privileged local user to bypass administrator password protection in UEFI. System administrators and security teams should assess exposure and prioritize patching to prevent potential [truncated]

HIGH NVIDIA CVE published 2026-08-25

CVE-2026-24263

A vulnerability in NVIDIA DGX Spark system firmware could allow a privileged attacker to cause a NULL pointer dereference, potentially leading to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. DGX Spark users should assess exposure, prioritize verification of affected versions, and review potential remediation.