DSA-2026-119: Security Update for NVIDIA Bluefield, ConnectX and DOCA Vulnerabilities
Riepilogo: Dell PowerEdge Server remediation is available for NVIDIA Bluefield, ConnectX and DOCA vulnerabilities that could be exploited by malicious users to compromise the affected systems.
Impatto
High
Dettagli
|
Third-party Component |
CVEs |
More Information |
|
NVIDIA DOCA |
CVE-2025-23257, CVE-2025-23258 |
|
|
ConnectX |
CVE-2025-23262 |
Prodotti interessati e correzione
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2025-23257, CVE-2025-23258 |
PowerEdge |
NVIDIA DOCA |
Versions prior to 3.2.1-044000 |
Version 3.2.1-044000 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverId=2RFDP |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-5 |
Versions prior to 16.35.80.02 |
Version 16.35.80.02 or later |
https://www.dell.com/support/home/drivers/DriversDetails?driverId=P5F14 |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-6 LX |
Versions prior to 26.46.30.48 |
Version 26.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=xm2gy |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-6 DX |
Versions prior to 22.46.30.48 |
Version 22.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=vvjfw |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-7 |
Versions prior to 28.46.30.48 |
Version 28.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=4y00c |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-8 |
Versions prior to 40.46.3048 |
Version 40.46.3048 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=t7c7x |
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2025-23257, CVE-2025-23258 |
PowerEdge |
NVIDIA DOCA |
Versions prior to 3.2.1-044000 |
Version 3.2.1-044000 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverId=2RFDP |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-5 |
Versions prior to 16.35.80.02 |
Version 16.35.80.02 or later |
https://www.dell.com/support/home/drivers/DriversDetails?driverId=P5F14 |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-6 LX |
Versions prior to 26.46.30.48 |
Version 26.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=xm2gy |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-6 DX |
Versions prior to 22.46.30.48 |
Version 22.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=vvjfw |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-7 |
Versions prior to 28.46.30.48 |
Version 28.46.30.48 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=4y00c |
|
CVE-2025-23262 |
PowerEdge |
ConnectX-8 |
Versions prior to 40.46.3048 |
Version 40.46.3048 or later |
https://www.dell.com/support/home/drivers/driversdetails?driverid=t7c7x |
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- Dell doesn't provide driver updates for Nvidia BlueField-2 & BlueField-3 devices which are also impacted by CVE-2025-23256. For specific drivers and firmware please visit- Security Bulletin: NVIDIA Bluefield, ConnectX, DOCA
- Dell doesn't provide driver updates for all versions of NVIDIA DOCA. For the specific NVIDIA drivers and firmware please visit- Security Bulletin: NVIDIA Bluefield, ConnectX, DOCA
Cronologia delle revisioni
|
Revision |
Date |
Description |
|
1.0 |
2026-02-26 |
Initial Release |
|
2.0 |
2026-03-11 |
Updated the “AFFECTED PRODUCTS AND REMEDIATION” table with ConnectX-5 details. |