GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Run:ai: Improper restriction of communication channels lets an attacker on an adjacent network reach

CVE-2025-33176NVIDIA / GPU stackcurated

Impact

Improper restriction of communication channels lets an attacker on an adjacent network reach privilege escalation, data tampering and information disclosure in the Run:ai scheduler. Run:ai is the component deciding which tenant's job lands on which GPU, so control over it is control over the fleet's allocation and quota model.

Who can reach it

Adjacent network, low privileges, user interaction, high complexity. A tenant workload or a compromised pod inside the cluster network.

What to do

Upgrade Run:ai per bulletin 5719. Cost: a control-plane upgrade - the scheduler restarts, queued jobs pause, running jobs keep their GPUs. Plan it in a low-submission window rather than draining nodes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.