NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information
NVIDIA patches 14 flaws in Linux Infrastructure Controller, including a critical CVSS 9.8 hardcoded credential issue.
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities. The most critical flaw, CVE-2026-65113 (CVSS 9.8), involves hardcoded credentials that could allow a remote, unauthenticated attacker to gain elevated privileges. Other high-severity issues include SQL injection (CVE-2026-65128), OS command injection (CVE-2026-65130), and missing authentication. The update affects versions 0 through 1.9, and organizations are advised to upgrade to version 2.0 or later.
- NVIDIA patched 14 vulnerabilities in Infrastructure Controller for Linux.
- Critical flaw CVE-2026-65113 allows remote code execution via hardcoded credentials (CVSS 9.8).
- SQL injection (CVE-2026-65128) and OS command injection (CVE-2026-65130) also patched.
- Organizations must update to version 2.0 or later.
Vulnerabilities mentionedAll →
- CVE-2026-651139.8—Hard-Coded Credentials in NVIDIA Infrastructure Controller for Linuxpublished · NVIDIA Infrastructure Controller for Linux+9 related
- CVE-2026-651187.5—Improper Certificate Validation in NVIDIA Infrastructure Controller for Linuxpublished · NVIDIA Infrastructure Controller for Linux+3 related
Full article612 words · extracted from cybersecuritynews.com · click to collapse
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments.
The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1.9. NVIDIA recommends that organizations clone or update the software to version 2.0 or later to address all reported issues.
Among the patched flaws is CVE-2026-65127, a medium-severity vulnerability caused by uncleared debug information. The issue carries a CVSS score of 4.1 and is tracked as CWE-1258.
An attacker with local access, high privileges, and favorable conditions could potentially retrieve sensitive system information left exposed through debugging artifacts.
While the debug-information issue requires significant attacker access, it is part of a broader security update containing several more serious vulnerabilities.
NVIDIA Fixes Linux Component Flaws
The most critical flaw, CVE-2026-65113, received a CVSS score of 9.8. NVIDIA said the issue involves hard-coded credentials in Infrastructure Controller for Linux.
A remote, unauthenticated attacker could potentially exploit the vulnerability to gain elevated privileges, manipulate data, cause a denial-of-service condition, or disclose information.
NVIDIA also fixed CVE-2026-65128, an SQL injection vulnerability with a CVSS score of 8.8. Successful exploitation may allow code execution, data manipulation, service disruption, and information disclosure. The flaw requires low privileges but no user interaction.
Other high-severity issues include missing or improper authentication weaknesses, OS command injection, and improper certificate validation.
| CVE ID | Vulnerability | CVSS v3.1 | Severity | CWE |
|---|---|---|---|---|
| CVE-2026-65113 | Use of hard-coded credentials | 9.8 | Critical | CWE-798 |
| CVE-2026-65128 | SQL injection | 8.8 | High | CWE-89 |
| CVE-2026-65114 | Missing authentication for critical function | 8.3 | High | CWE-306 |
| CVE-2026-65121 | Improper authentication | 8.2 | High | CWE-287 |
| CVE-2026-65130 | OS command injection | 8.0 | High | CWE-78 |
| CVE-2026-65118 | Improper certificate validation | 7.5 | High | CWE-295 |
| CVE-2026-65129 | Improper certificate validation | 6.7 | Medium | CWE-295 |
| CVE-2026-65125 | External control of file name or path | 6.6 | Medium | CWE-73 |
| CVE-2026-65115 | Uncontrolled resource consumption | 6.5 | Medium | CWE-400 |
| CVE-2026-65112 | Uncontrolled resource consumption | 6.5 | Medium | CWE-400 |
| CVE-2026-65124 | XML injection | 5.9 | Medium | CWE-91 |
| CVE-2026-65126 | Improper enforcement of behavioral workflow | 5.0 | Medium | CWE-841 |
| CVE-2026-65117 | Use of hard-coded password | 5.0 | Medium | CWE-259 |
| CVE-2026-65127 | Exposure of sensitive system information through uncleared debug information | 4.1 | Medium | CWE-1258 |
CVE-2026-65114, rated 8.3, could allow data tampering, denial of service, and information disclosure because a critical function lacked proper authentication. CVE-2026-65121, rated 8.2, could permit privilege escalation and data exposure through improper authentication.
The update also resolves CVE-2026-65130, an OS command injection issue with a CVSS score of 8.0. Although exploitation requires high privileges and a high attack complexity, a successful attack could lead to code execution and a complete compromise of confidentiality, integrity, and availability.
Additional fixes address two uncontrolled resource consumption vulnerabilities, CVE-2026-65115 and CVE-2026-65112, both rated 6.5. An authenticated attacker could exploit these issues to cause denial-of-service conditions.
NVIDIA also remediated external control of file paths, XML injection, hard-coded password use, certificate-validation issues, and improper workflow enforcement.
Infrastructure Controller deployments may be used in environments that manage NVIDIA infrastructure components, making timely remediation important.
Organizations should identify systems running Infrastructure Controller versions 0 through 1.9, update them to version 2.0 or later, and review exposed services, access controls, credentials, logs, and network segmentation.
NVIDIA noted that its severity ratings reflect average risk across varied deployments and may not represent the risk to every local installation. Security teams should evaluate exposure based on their configurations, user privileges, network accessibility, and the affected controller’s operational role.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.