-
A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 (18-03-2025)
Preface: Stateless applications perform tasks based on the input provided in the current transaction. These applications make use of Content Delivery Network (CDN) and web to process short term requests. Unlike stateful applications, stateless applications do not save users data. There is no stored knowledge or information for reference to past records. Containers are widely…
-
Arm CPU Security Update: Training in Transient Execution Attacks (17th Mar 2025)
Initial release: August 8, 2023 Last updated: 14 Mar 2025 Preface: AMD’s Zen3 and Zen4 architectures are not directly related to ARM design, as they are based on AMD’s own x86-64 architecture. ARM is concerned about Training in Transient Execution (TTE) attacks because these attacks exploit vulnerabilities in speculative execution, which can affect ARM processors…
-
CVE-2025-21424: Memory corruption while calling the NPU driver APIs concurrently (16th Mar 2025)
NVD Published Date: 03/03/2025NVD Last Modified: 03/07/2025 Preface: Real-time processing of sensor data for tasks like obstacle detection and navigation is crucial, making NPUs ideal for these applications. NPUs help in real-time decision-making and control, which is essential for robotic applications. While NPUs are highly efficient for specific AI applications, they cannot replace GPUs due…
-
CVE-2025-23242 & CVE-2025-23243:NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue (13th Mar 2025)
Preface: NeMo is an open source PyTorch-based toolkit for research in conversational AI that exposes more of the model and PyTorch internals. Riva supports the ability to import supported models trained in NeMo. NVIDIA Riva is a GPU-accelerated SDK for building Speech AI applications, customized for your use case, and delivering real-time performance. Background: NVIDIA…
-
CVE‑2025‑23360 – NVIDIA Nemo Framework contains a vulnerability (12th Mar 2025)
Preface: The symbol ~/. by itself is not a relative path traversal; it simply refers to the home directory of the current user. However, when combined with ./.., it can be part of a relative path traversal. Relative path traversal involves using sequences like ../ to navigate up the directory hierarchy. For example, ~/. refers…
-
CVE-2024-36347: Improper signature verification in AMD CPU ROM microcode patch loader (11th Mar 2025)
Originally published on March 5, 2025 Preface: The microcode patch loader in the CPU’s ROM (Read-Only Memory) is responsible for loading these updates into the CPU during the boot process. This ensures that the CPU runs the latest microcode, which can include important security and functionality improvements Background: The System Management Mode (SMM) execution environment…
-
CVE-2025-22412: Fix more memory-unsafe logging (10th Mar 2025)
Preface: In smartphones, the System on Chip (SoC), such as those made by Qualcomm, integrates various components including the CPU, GPU, and memory. The embedded OS and applications run on this SoC, utilizing its built-in memory (RAM) for processing tasks.The flash storage (often referred to as flashdisk) in smartphones is primarily used for storing persistent…
-
CVE-2024-0141: NVIDIA Hopper HGX for 8-GPU contains a vulnerability in GPU vBIOS (10th Mar2025)
Last official update on February 28, 2025 at 3:28 PM Preface: Hopper PPCIe is limited to HGX 8-way systems, where the eight GPUs and four NVSwitches are passed through to one VM. Other topologies are not supported. Background: The GPU vBIOS can communicate through IOCTL (Input/Output Control) calls. IOCTL is a system call for device-specific…
-
CVE-2024-0114: NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller HMC (7 th March 2025)
Preface: NVIDIA collaborates with Supermicro for their server solutions, including the use of Supermicro’s BMC (Baseboard Management Controller) in certain systems. Supermicro provides a range of server solutions optimized for NVIDIA’s platforms. Background: The NVIDIA Hopper HGX for 8 GPUs has several standout features: High Performance: It hosts eight H100 Tensor Core GPUs, which are…
-
2024-53022: Memory corruption may occur during communication between primary and guest VM (6th Mar 2025)
Preface: QNX hypervisors are available in two variants: QNX Hypervisor and QNX Hypervisor for Safety. The QNX Hypervisor variant (QH), which includes QNX Hypervisor 8.0, is not a safety-certified product. It must not be used in a safety-related production system. If you are building a safety-related system, you must use the QNX Hypervisor for Safety…