Path Manipulation Flaw in NVIDIA Infrastructure Controller for Linux Could Enable RCE
AI analysis
CVE-2026-65125 is an external control of file name or path vulnerability (CWE-73) in the NVIDIA Infrastructure Controller for Linux, a management component used to administer NVIDIA GPU data center clusters. An attacker who already holds highly privileged access (the CVSS vector requires high privileges) to a network-reachable controller could supply attacker-controlled file names or paths, causing the software to read or write files outside intended locations. Successful exploitation could yield code execution, privilege escalation, data tampering, and denial of service on the managed infrastructure. The flaw is one of 14 vulnerabilities NVIDIA disclosed in the Infrastructure Controller that collectively enable code execution and privilege escalation. There is no known public proof of concept, it is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Patch to the version specified in NVIDIA's PSIRT advisory for this 14-flaw bundle as soon as it is available, since this issue chains with other flaws in the same product that could lower the bar to code execution. Restrict network access to the Infrastructure Controller management interface to trusted admin subnets and limit which accounts hold the high-privilege roles needed to trigger this flaw. Review the controller host and managed nodes for unexpected file writes, new privileged processes, or configuration tampering that could indicate a successful path-manipulation attempt.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
nicheunknown; plausibly low thousands of enterprise GPU cluster deployments (order of magnitude only) — The Infrastructure Controller is enterprise data-center management software for NVIDIA GPU clusters rather than a mass-market product, and management interfaces are typically deployed on private admin networks, so no public install counts…
Description
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.