CVE-2025-33216 PUBLISHED

Assigner: nvidia
Reserved: 15.04.2025 Published: 24.03.2026 Updated: 24.03.2026

NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an incorrect calculation of buffer size by sending crafted configurations. A successful exploit of this vulnerability may lead to crash of the SNAP service, causing denial of service of the storage service to the host.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Score: 6.8

Product Status

Vendor NVIDIA
Product SNAP-4 Container
Versions Default: unaffected
  • Version All versions prior to SNAP-4.9.0 and SNAP-4.5.5 is affected

References

Problem Types

  • CWE-131 Incorrect Calculation of Buffer Size CWE

Impacts

  • Denial of service