AI analysis
CVE-2026-65124 is an XML injection flaw (CWE-91) in NVIDIA's Infrastructure Controller for Linux, a management component of NVIDIA enterprise AI infrastructure. Exploitation occurs over the network but requires the attacker to already hold high privileges on the system and involves high attack complexity, meaning it is not a trivial remote attack. A successful exploit lets the attacker tamper with data (high integrity impact) and cause denial of service (high availability impact), but does not compromise confidentiality. Organizations running NVIDIA GPU/AI cluster management tooling on Linux are the affected population, and this flaw was disclosed as part of a batch of 14 vulnerabilities in the product, several of which enable code execution and privilege escalation. There is no known public proof of concept, it is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Upgrade NVIDIA Infrastructure Controller for Linux to the fixed release specified in NVIDIA's security bulletin for this 14-flaw batch, prioritizing it alongside the code-execution and privilege-escalation issues disclosed at the same time. Restrict network access to the controller to trusted management networks and limit the highly privileged accounts that could be leveraged to trigger the injection, since exploitation requires high privileges. Review controller-managed configuration and data for unexpected tampering or availability issues as part of post-patch validation.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
nicheLikely low thousands of enterprise NVIDIA AI-cluster deployments worldwide (order-of-magnitude estimate, no public counts) — The Infrastructure Controller ships only as part of NVIDIA enterprise AI/GPU infrastructure (datacenter cluster management) rather than as a broadly installed or internet-facing product, and no public active-install or internet-scan counts…