NVIDIA has addressed a critical vulnerability in its BlueField technology, identified as CVE-2026-65094, which scores a CVSS of 9.0. The flaw in the VIRTIO-Net component could allow a virtual machine user to execute arbitrary code. This vulnerability is concerning as BlueField DPUs manage networking in cloud and data center environments, making them essential for maintaining security boundaries. The vulnerability arises from a Write-What-Where condition, enabling attackers to manipulate memory with low privileges.
Affected versions include various branches of VIRTIO-Net, with patches now available. Users are urged to update to secure versions immediately.