NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments.

The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1.9. NVIDIA recommends that organizations clone or update the software to version 2.0 or later to address all reported issues.

Among the patched flaws is CVE-2026-65127, a medium-severity vulnerability caused by uncleared debug information. The issue carries a CVSS score of 4.1 and is tracked as CWE-1258.

An attacker with local access, high privileges, and favorable conditions could potentially retrieve sensitive system information left exposed through debugging artifacts.

While the debug-information issue requires significant attacker access, it is part of a broader security update containing several more serious vulnerabilities.

NVIDIA Fixes Linux Component Flaws

The most critical flaw, CVE-2026-65113, received a CVSS score of 9.8. NVIDIA said the issue involves hard-coded credentials in Infrastructure Controller for Linux.

A remote, unauthenticated attacker could potentially exploit the vulnerability to gain elevated privileges, manipulate data, cause a denial-of-service condition, or disclose information.

NVIDIA also fixed CVE-2026-65128, an SQL injection vulnerability with a CVSS score of 8.8. Successful exploitation may allow code execution, data manipulation, service disruption, and information disclosure. The flaw requires low privileges but no user interaction.

Other high-severity issues include missing or improper authentication weaknesses, OS command injection, and improper certificate validation.

CVE ID Vulnerability CVSS v3.1 Severity CWE
CVE-2026-65113 Use of hard-coded credentials 9.8 Critical CWE-798
CVE-2026-65128 SQL injection 8.8 High CWE-89
CVE-2026-65114 Missing authentication for critical function 8.3 High CWE-306
CVE-2026-65121 Improper authentication 8.2 High CWE-287
CVE-2026-65130 OS command injection 8.0 High CWE-78
CVE-2026-65118 Improper certificate validation 7.5 High CWE-295
CVE-2026-65129 Improper certificate validation 6.7 Medium CWE-295
CVE-2026-65125 External control of file name or path 6.6 Medium CWE-73
CVE-2026-65115 Uncontrolled resource consumption 6.5 Medium CWE-400
CVE-2026-65112 Uncontrolled resource consumption 6.5 Medium CWE-400
CVE-2026-65124 XML injection 5.9 Medium CWE-91
CVE-2026-65126 Improper enforcement of behavioral workflow 5.0 Medium CWE-841
CVE-2026-65117 Use of hard-coded password 5.0 Medium CWE-259
CVE-2026-65127 Exposure of sensitive system information through uncleared debug information 4.1 Medium CWE-1258

CVE-2026-65114, rated 8.3, could allow data tampering, denial of service, and information disclosure because a critical function lacked proper authentication. CVE-2026-65121, rated 8.2, could permit privilege escalation and data exposure through improper authentication.

The update also resolves CVE-2026-65130, an OS command injection issue with a CVSS score of 8.0. Although exploitation requires high privileges and a high attack complexity, a successful attack could lead to code execution and a complete compromise of confidentiality, integrity, and availability.

Additional fixes address two uncontrolled resource consumption vulnerabilities, CVE-2026-65115 and CVE-2026-65112, both rated 6.5. An authenticated attacker could exploit these issues to cause denial-of-service conditions.

NVIDIA also remediated external control of file paths, XML injection, hard-coded password use, certificate-validation issues, and improper workflow enforcement.

Infrastructure Controller deployments may be used in environments that manage NVIDIA infrastructure components, making timely remediation important.

Organizations should identify systems running Infrastructure Controller versions 0 through 1.9, update them to version 2.0 or later, and review exposed services, access controls, credentials, logs, and network segmentation.

NVIDIA noted that its severity ratings reflect average risk across varied deployments and may not represent the risk to every local installation. Security teams should evaluate exposure based on their configurations, user privileges, network accessibility, and the affected controller’s operational role.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information appeared first on Cyber Security News.