CVE Vulnerabilities

CVE-2023-25506

Access of Memory Location After End of Buffer

Published: Apr 22, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

Weakness

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

Affected Software

Name Vendor Start Version End Version
Sbios Nvidia * 52w_3a13 (excluding)

References