NVIDIA Resiliency Extension for Linux Log Aggregation Vulnerability Allowing Privilege Escalation and Code Execution
Vulnerability
A vulnerability exists in the log aggregation component of the NVIDIA Resiliency Extension for Linux. This issue allows an attacker to create predictable log file names, which could be exploited to escalate privileges, execute code, cause a denial of service, disclose information, or tamper with data.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, execution of arbitrary code, disruption of service, unauthorized information disclosure, and unauthorized data modification.
Remediation
Users are advised to update to version 0.5.0 or later. The updated version is available on the NVIDIA Resiliency Extension GitHub page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
