NVIDIA has recently revealed a significant security flaw in its BlueField Data Processing Units (DPUs) and ConnectX networking platforms. This flaw, if exploited, could allow malicious actors to execute unauthorized code, posing a severe threat to affected systems.
High-Risk Vulnerability Details
Identified as CVE-2026-65094, this vulnerability affects the VIRTIO-Net component and has been assigned a CVSS v3.1 score of 9.0. This rating highlights its high-risk potential, particularly concerning enterprise and cloud environments. According to a July 2026 security bulletin from NVIDIA, the BlueField-3 Virtio-Net contains a CWE-123 write-what-where vulnerability, which permits attackers to manipulate memory by writing arbitrary data to unintended locations.
Such vulnerabilities are particularly alarming as they can lead to the execution of attacker-controlled code, thereby threatening the integrity and confidentiality of the systems involved.
Attack Scenarios and Implications
The primary attack scenario involves a low-privilege virtual machine (VM) user crafting a malicious payload to exploit this vulnerability. Because the attack vector is adjacent and requires no user interaction, it poses a significant threat to shared or multi-tenant environments, like cloud infrastructures and virtualized data centers.
Moreover, the vulnerability includes a scope change, allowing exploitation to extend beyond the initially compromised component. This amplifies its severity in production settings, where BlueField DPUs handle critical networking, storage, and security tasks. A breach at this level could allow attackers to bypass traditional security measures, move laterally within networks, or disrupt traffic processing.
Versions Affected and Mitigation Steps
The vulnerability impacts multiple VIRTIO-Net versions, including general availability and long-term support releases. Specifically, it affects all versions before 25.10.6 for GA, 25.10.2 for LTS25, 24.10.50 for LTS24, and 23.10.23 for LTS23. NVIDIA has issued patched versions to address this issue and strongly advises organizations to update immediately to prevent potential exploitation.
Although no active exploitation has been reported as of the disclosure date, the company underscores the importance of assessing infrastructure vulnerabilities, particularly when untrusted VMs or tenants have access to shared resources. The risk assessment is an average and may not fully capture specific exposure levels across various environments.
Organizations are urged to secure their systems by applying available patches, restricting access to untrusted VMs, and monitoring abnormal network activities as part of a comprehensive defense strategy. Updates are available through NVIDIA’s product security portal and DOCA VIRTIO-Net distribution channels.
This incident underscores the critical nature of addressing write-what-where vulnerabilities promptly, given their history of exploitation in real-world scenarios.
