CVE-2025-23259Race Condition in Dpdk

CWE-362Race Condition6 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.0%
top 87.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateOct 9

Description

NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages5 packages

CVEListV5nvidia/mellanox_dpdk_20.11All versions prior to 20.11_7.8.0 LTS
CVEListV5nvidia/mellanox_dpdk_22.11All versions prior to 22.11_2310 LTS, All versions prior to 22.11_2410 LTS, All versions prior to 22.11_2504.1.0+2
CVEListV5nvidia/upstream_dpdk4 versions+3
debiandebian/dpdk< dpdk 24.11.3-1 (forky)
Debiandpdk/dpdk< 24.11.3-1~deb13u1+1

🔴Vulnerability Details

3
GHSA
GHSA-xq47-rgwp-c6c5: NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information di2025-09-05
CVEList
CVE-2025-23259: NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information di2025-09-04
OSV
CVE-2025-23259: NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information di2025-09-04

📋Vendor Advisories

2
Ubuntu
DPDK vulnerability2025-10-09
Debian
CVE-2025-23259: dpdk - NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where a...2025