CVE-2025-23263 Details
Description
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.
A vulnerability has been identified in NVIDIA DOCA-Host and Mellanox OFED, specifically within the VGT+ feature. This vulnerability allows an attacker on a virtual machine to escalate privileges and cause a denial-of-service on the VLAN. The issue arises when VGT+ is enabled and eSwitch is in Legacy mode, the default setting.
Users can update to NVIDIA DOCA-Host versions 2.5.4-0.0.9, 2.9.3-0.2.2, or 3.0.0-058001. For Mellanox OFED, users should update to versions 5.8-7.0.6.1, 23.10-5.1.4.0, or 24.10-3.2.5.0. To check if VGT+ is enabled, look for the 'trunk' file in the '/sys/class/net/eth5/device/sriov/0/' directory. If the file is missing or empty, VGT+ is not enabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2025CISA-ADP
Assessed Jul 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5654 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-279 | Incorrect Execution-Assigned Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA DOCA-Host | All versions |
CPE
Remediation
| |
| NVIDIA Mellanox OFED | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2025 | New CVE Received | [email protected] |
Volerion