We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-23263



Description

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.

Reserved 2025-01-14 | Published 2025-07-17 | Updated 2025-07-17 | Assigner nvidia


HIGH: 7.6CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Problem types

CWE-279: Incorrect Execution-Assigned Permissions

Product status

Default status
unaffected

DOCA-Host All versions prior to 2.5.4-0.0.9
affected

DOCA-Host All versions prior to 2.9.3-0.2.2
affected

DOCA-Host All versions prior to 3.0.0-058001
affected

Mellanox OFED All versions prior to 5.8-7.0.6.1
affected

Mellanox OFED All versions prior to 23.10-5.1.4.0
affected

Mellanox OFED All versions prior to 24.10-3.2.5.0
affected

References

nvidia.custhelp.com/app/answers/detail/a_id/5654

cve.org (CVE-2025-23263)

nvd.nist.gov (CVE-2025-23263)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-23263

Support options

Helpdesk Chat, Email, Knowledgebase