GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Resiliency Extension: Predictable log-file names in the log-aggregation path let an attacker pre-create

CVE-2025-33225NVIDIA / GPU stackcurated

Impact

Predictable log-file names in the log-aggregation path let an attacker pre-create or hijack the target file, reaching privilege escalation and code execution. Scored 8.4 with no privileges required. The Resiliency Extension is what restarts failed large training jobs, so it runs with broad access across the job's nodes.

Who can reach it

Local, no privileges required, no user interaction. Any account on a node participating in a resilient training job.

What to do

Update the Resiliency Extension per bulletin 5746 and rebuild training images. Cost: image rebuild and job restart; no host driver or firmware change.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.