{ "document": { "aggregate_severity": { "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale", "text": "CRITICAL" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 2026 NVIDIA Corporation. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "details", "text": "1161541", "title": "Product Information Delivery" }, { "category": "details", "text": "TB-12986-001_v01", "title": "Part Number" }, { "category": "details", "text": "false", "title": "Contains Firmware" }, { "category": "details", "text": "OTHER:Other", "title": "Product Team" }, { "category": "summary", "text": "NVIDIA has released a software update for NVIDIA Infrastructure Controller. 
To protect your system, clone or update this software from the NVIDIA/infra-controller GitHub repo.
", "title": "Summary" }, { "category": "details", "text": "NVIDIA has released a software update for NVIDIA Infrastructure Controller. 
To protect your system, clone or update this software from the NVIDIA/infra-controller GitHub repo.
", "title": "Security Update Notes" }, { "category": "details", "text": "NVIDIA has released a software update for NVIDIA\u00ae Infrastructure Controller. 
To protect your system, clone or update this software from the NVIDIA/infra-controller GitHub repo to Version 2.0 or later. 
", "title": "Mitigation Notes" }, { "category": "legal_disclaimer", "text": "ALL NVIDIA INFORMATION, DESIGN SPECIFICATIONS, REFERENCE BOARDS, FILES, DRAWINGS, DIAGNOSTICS, LISTS, AND OTHER DOCUMENTS (TOGETHER AND SEPARATELY, \"MATERIALS\") ARE BEING PROVIDED \"AS IS.\" NVIDIA MAKES NO WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE WITH RESPECT TO THE MATERIALS, AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OR CONDITION OF TITLE, MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT, ARE HEREBY EXCLUDED TO THE MAXIMUM EXTENT PERMITTED BY LAW.\n\nInformation is believed to be accurate and reliable at the time it is furnished. However, NVIDIA Corporation assumes no responsibility for the consequences of use of such information or for any infringement of patents or other rights of third parties that may result from its use. No license is granted by implication or otherwise under any patent or patent rights of NVIDIA Corporation. Specifications mentioned in this publication are subject to change without notice. This publication supersedes and replaces all information previously supplied. NVIDIA Corporation products are not authorized for use as critical components in life support devices or systems without express written approval of NVIDIA Corporation.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.nvidia.com/security/report-vulnerability/", "issuing_authority": "NVIDIA Product Security is responsible for vulnerability handling across all NVIDIA products and services.", "name": "NVIDIA Product Security", "namespace": "https://www.nvidia.com/security" }, "title": "Security Bulletin - NVIDIA Infrastructure Controller - August 2026", "tracking": { "current_release_date": "2026-09-22T00:00:00Z", "generator": { "date": "2026-09-22T00:00:00Z", "engine": { "name": "NVIDIA PSIRT", "version": "2.0.0" } }, "id": "5879", "initial_release_date": "2026-09-22T00:00:00Z", "revision_history": [ { "date": "2026-09-22", "number": "1.0.0", "summary": "Initial Release" } ], "status": "final", "version": "1.0.0" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "NVIDIA Infrastructure Controller", "product": { "name": "NVIDIA Infrastructure Controller", "product_id": "linux_nvidia_infrastructure_controller", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:nvidia_infrastructure_controller:*:*:*:*:*:*:*:*" } } } ], "category": "product_family", "name": "NVIDIA Product Family" }, { "branches": [ { "category": "product_version", "name": "NVIDIA Infrastructure Controller", "product": { "name": "0 to 1.9", "product_id": "linux_nvidia_infrastructure_controller_0_to_1_9", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:nvidia_infrastructure_controller:0_to_1_9:*:*:*:*:*:*:*" } } }, { "category": "product_version", "name": "NVIDIA Infrastructure Controller", "product": { "name": "2.0", "product_id": "linux_nvidia_infrastructure_controller_2_0", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:nvidia_infrastructure_controller:2_0:*:*:*:*:*:*:*" } } } ], "category": "architecture", "name": "Linux" } ], "category": "vendor", "name": "NVIDIA" } ] }, "vulnerabilities": [ { "acknowledgments": [ { "names": [ "Faisal Tameesh" ] } ], "cve": "CVE-2026-65121", "cwe": { "id": "CWE-287", "name": "Improper Authentication" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.", "title": "Vulnerability description" }, { "category": "details", "text": "escalation of privileges, data tampering, information disclosure", "title": "Impacts" }, { "category": "details", "text": "6420590", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65121" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65121" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 8.2, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65124", "cwe": { "id": "CWE-91", "name": "XML Injection (aka Blind XPath Injection)" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service", "title": "Impacts" }, { "category": "details", "text": "6025252", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65124" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65124" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 5.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65125", "cwe": { "id": "CWE-73", "name": "External Control of File Name or Path" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "code execution, escalation of privileges, data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5996720", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65125" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65125" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.6, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65126", "cwe": { "id": "CWE-841", "name": "Improper Enforcement of Behavioral Workflow" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5999719", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65126" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65126" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.0, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65127", "cwe": { "id": "CWE-1258", "name": "Exposure of Sensitive System Information Due to Uncleared Debug Information" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "information disclosure", "title": "Impacts" }, { "category": "details", "text": "6025253", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65127" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65127" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 4.1, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65128", "cwe": { "id": "CWE-89", "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "code execution, data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5996304", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65128" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65128" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65129", "cwe": { "id": "CWE-295", "name": "Improper Certificate Validation" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "6025251", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65129" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65129" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "LOW", "baseScore": 6.7, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65130", "cwe": { "id": "CWE-78", "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "code execution, data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5996484", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65130" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65130" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.0, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65113", "cwe": { "id": "CWE-798", "name": "Use of Hard-coded Credentials" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "escalation of privileges, data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5996597", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65113" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65113" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65114", "cwe": { "id": "CWE-306", "name": "Missing Authentication for Critical Function" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "6022893", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65114" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65114" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.3, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65115", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "denial of service", "title": "Impacts" }, { "category": "details", "text": "6022895", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65115" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65115" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65117", "cwe": { "id": "CWE-259", "name": "Use of Hard-coded Password" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "6022894", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65117" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65117" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "LOW", "baseScore": 5.0, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65118", "cwe": { "id": "CWE-295", "name": "Improper Certificate Validation" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "data tampering, denial of service, information disclosure", "title": "Impacts" }, { "category": "details", "text": "5999702", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65118" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65118" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "LOW", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-65112", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "notes": [ { "category": "summary", "text": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "denial of service", "title": "Impacts" }, { "category": "details", "text": "6022896", "title": "defect" } ], "product_status": { "fixed": [ "linux_nvidia_infrastructure_controller_2_0" ], "known_affected": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] }, "references": [ { "category": "external", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65112" }, { "category": "external", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65112" } ], "release_date": "2026-09-22T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "linux_nvidia_infrastructure_controller_0_to_1_9" ] } ] } ] }