9.9

CVE-2026-65083

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nvidia ≫ Openshell Version <= 0.0.33
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.411
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Nvidia 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

https://github.com/NVIDIA/product-security/tree/main/2026/5872
Product
https://nvd.nist.gov/vuln/detail/CVE-2026-65083
Third Party Advisory
US Government Resource
https://www.cve.org/CVERecord?id=CVE-2026-65083
Third Party Advisory