BlueField DPU: Access-control bypass on the DPU
Impact
Access-control bypass on the DPU -> control of the tenant network path
Who can reach it
Network-adjacent attacker / tenant on the DPU-served host
What to do
Flash DPU firmware + upgrade DOCA; DPU reset drops tenant networking, drain node
Fleet impact
How widespread
very common - ConnectX NICs are in essentially every GPU node; BlueField DPUs increasingly own the tenant network and storage path
Cost to remediate
firmware-flash of NIC/DPU firmware per node (BF-2/BF-3 images 45.1020, 35.4554 LTS22, 39.5050 LTS23, 43.3608 LTS24), often requiring a host reboot to activate
Why it hits the whole fleet
The DPU is a full independent computer with DMA to the host and control of the tenant's network and storage offload - compromise is below the hypervisor and invisible to the host OS, on every node carrying the card.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.