This NVIDIA safety flaw might let attackers crash GPU monitoring providers


We’re used to listening to about GPUs overheating or energy connectors melting. But this time, the risk comes from software program that displays NVIDIA’s GPUs and will have allowed attackers to disrupt susceptible servers.

Researchers at safety agency Lava uncovered a high-severity vulnerability in NVIDIA’s DCGM Exporter. Tracked as ‘CVE-2026-47483’, and it has a CVSS score of 8.2 out of 10, for which a repair has been launched by NVIDIA.

What is NVIDIA DCGM Exporter?

What does it do?

DCGM Exporter is a monitoring device that maintains and displays the well being of NVIDIA GPUs. This open-source device collects GPU knowledge corresponding to temperature, reminiscence utilization, energy consumption, efficiency, and errors. Tools like Prometheus learn this info and ship it to directors to watch their techniques.

Think of it as a well being monitor for a GPU server. The essential concern arises when this stage of knowledge is obtainable publicly with out approved entry.

What is the vulnerability?

How does it work?

According to Michael Katchinskiy from Lava, “About 1 / 4 of the uncovered DCGM hosts in our scan have been serving Go’s /debug/pprof/ profiling endpoints alongside /metrics.” This means the DCGM Exporter device by chance uncovered a debugging function known as pprof, which exhibits how a lot reminiscence and processing energy a program is utilizing.

An unauthenticated attacker might ship a number of requests to those hidden profiling endpoints, forcing the server to eat monumental reminiscence and CPU energy, leading to a Denial of Service(DoS) assault, thereby crashing the monitoring device, blinding operators to GPU well being and exercise, and dragging down AI work working on the identical machine.

It affected a number of techniques

What do the numbers say?

“The uncovered techniques included NVIDIA Blackwell Ultra B300 GPUs, H200s and H100s used for large-scale AI workloads, in addition to shopper RTX 5090 and 4090 techniques,” Michael stated.

During the 4 scans between March and May 2026, the researchers discovered that knowledge from about 2,100 GPU servers was out there publicly, with none login. Together, these techniques revealed details about greater than 12,000 particular person GPUs, representing an estimated $100 million in {hardware}.

The report additionally talked about that shopper GPUs and mining farms accounted for round 35% of the uncovered techniques, exhibiting that the issue wasn’t restricted to giant AI knowledge facilities. On a regional foundation, the United States had the most important share, accounting for five,274 GPUs, or about 44% of all of the GPUs recognized within the scans.

NVIDIA has addressed the problem

A set model was launched

NVIDIA has addressed the vulnerability, and directors are suggested to improve DCGM Exporter to model 4.8.2 or later. It can also be advisable to limit entry to approved monitoring techniques solely and hold monitoring instruments on non-public networks, protected by firewalls.

With GPU prices hovering amid the continued AI growth, securing these invaluable techniques is extra vital than ever.



Source link