CVE-2025-33215 PUBLISHED

Assigner: nvidia
Reserved: 15.04.2025 Published: 24.03.2026 Updated: 24.03.2026

NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of storage to other VMs.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Score: 6.8

Product Status

Vendor NVIDIA
Product SNAP-4 Container
Versions Default: unaffected
  • Version All versions prior to SNAP-4.9.1 and SNAP-4.5.5 is affected

References

Problem Types

  • CWE-823 Use of Out-of-range Pointer Offset CWE

Impacts

  • Denial of service