Skip to main content

CVE-2025-23263: CWE-279: Incorrect Execution-Assigned Permissions in NVIDIA DOCA-Host and Mellanox OFED

High
VulnerabilityCVE-2025-23263cvecve-2025-23263cwe-279
Published: Thu Jul 17 2025 (07/17/2025, 17:19:50 UTC)
Source: CVE Database V5
Vendor/Project: NVIDIA
Product: DOCA-Host and Mellanox OFED

Description

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.

Technical Details

Data Version
5.1
Assigner Short Name
nvidia
Date Reserved
2025-01-14T01:06:23.291Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6879335fa83201eaace7af27

Added to database: 7/17/2025, 5:31:11 PM

Last updated: 7/17/2025, 5:31:11 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats