Resource-Exhaustion Denial of Service in NVIDIA Infrastructure Controller for Linux
AI analysis
CVE-2026-65112 is an uncontrolled resource consumption flaw (CWE-400) in NVIDIA Infrastructure Controller for Linux, a management component used in NVIDIA-based data center and AI cluster deployments. Because the CVSS vector requires only low privileges (PR:L) over a network with low attack complexity, an attacker with limited authenticated access to the controller can trigger resource exhaustion and crash or hang the service, causing denial of service. The impact is confined to availability — there is no confidentiality or integrity impact. This bug was disclosed alongside a broader set of 14 NVIDIA Infrastructure Controller vulnerabilities, some of which enable code execution and privilege escalation, though this specific CVE is DoS-only. There is no public proof of concept, it is not on the CISA KEV catalog, and no exploitation has been reported.
What to do: Apply NVIDIA's patched Infrastructure Controller for Linux release as specified in the NVIDIA PSIRT advisory, since no fixed version range is given here. While patching, treat this as part of the 14-flaw NVIDIA Infrastructure Controller advisory bundle and verify fixes for the code-execution and privilege-escalation issues as well. Restrict network access to the controller's management interface and tightly control low-privileged accounts, since exploitation requires only an authenticated foothold; monitor the service for abnormal resource consumption or repeated restarts.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.