CVE Vulnerabilities

CVE-2025-33194

Incorrect Behavior Order: Validate Before Canonicalize

Published: Nov 25, 2025 | Modified: Nov 28, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Affected Software

Name Vendor Start Version End Version
Dgx_os Nvidia * ota0 (excluding)

Potential Mitigations

References