TL;DR
NVIDIA patched a critical NVIDIA BlueField vulnerability tracked as CVE-2026-65094. The VIRTIO-Net flaw scores a CVSS of 9.0. A virtual machine user could trigger code execution in the affected component.
Why it matters
NVIDIA BlueField DPUs offload networking for cloud and data center hosts. Therefore they sit in a trusted spot between VMs and hardware. A flaw here can break the isolation that cloud tenants rely on. That makes any BlueField bug a priority for operators.
How the attack works
The bug is a Write-What-Where condition in VIRTIO-Net. According to NVIDIA, “a VM user may cause a Write-What-Where condition by crafted message.” As a result, the attacker gains a powerful memory-write primitive. NVIDIA adds that a successful exploit “may lead to code execution in Virtio-Net scope.” The attack vector is adjacent, and it needs only low privileges.
Affected versions
The NVIDIA BlueField vulnerability affects several VIRTIO-Net branches. VIRTIO-Net GA on BlueField 3 is affected before 25.10.6. LTS25 is affected before 25.10.2, and LTS24 before 24.10.50. LTS23 is affected at 1.7.21 and older. NVIDIA has not reported any exploitation in the wild.
Patch and mitigation
Update to the fixed builds now. NVIDIA lists the versions in its security bulletin. You can grab the packages from the DOCA downloads page. Move LTS23 systems to 23.10.23 or newer.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.