# CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution

> A CWE-123 write-what-where vulnerability (CVE-2026-65094, CVSS 9.0) in the VIRTIO-Net implementation on NVIDIA BlueField-3 DPUs and ConnectX networking platforms lets a low-privileged virtual machine user craft a malicious message to write arbitrary data to unintended memory locations, potentially achieving code execution beyond the VIRTIO-Net component in multi-tenant cloud/virtualized environments. NVIDIA discovered the flaw internally and shipped patched releases across all supported branches; no public PoC or active exploitation has been reported.

- **Published:** 2026-08-01T00:00:00Z
- **Last reviewed:** 2026-08-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1812
- **ID:** TL-2026-1812
- **Severity:** CRITICAL (CVSS 9)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-65094

## Description

CVE-2026-65094 is a CWE-123 write-what-where condition in NVIDIA's VIRTIO-Net implementation, the paravirtualized network device interface that BlueField-3 Data Processing Units (DPUs) and ConnectX networking adapters expose to guest virtual machines. According to NVIDIA's July 2026 security bulletin (referenced by multiple independent outlets as product-security-portal answer a_id/5815, titled "Security Bulletin: NVIDIA Networking BlueField, ConnectX - July 2026" per stack.watch's NVIDIA advisory index) and corroborating technical writeups, a virtual machine user holding only low privileges can send a specially crafted message to the VIRTIO-Net component that causes it to write attacker-controlled data to unintended memory locations. This write-what-where memory-corruption primitive can be escalated to arbitrary code execution within the VIRTIO-Net context.

The flaw carries a CVSS v3.1 base score of 9.0. Independent technical summaries consistently describe the attack vector as Adjacent (reachable by a VM sharing the host's virtual network fabric rather than the public internet), attack complexity Low, privileges required Low (a legitimate but unprivileged tenant VM account), no user interaction, and a scope change -- meaning successful exploitation can affect resources beyond the vulnerable VIRTIO-Net component itself, i.e. the host/DPU context, with full confidentiality, integrity, and availability impact. Reconstructing the CVSS 3.1 vector from these individually-sourced qualitative descriptors (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) mathematically reproduces the reported 9.0 base score, corroborating the secondary reporting even though NVIDIA's own bulletin page could not be directly retrieved (HTTP 403 on two separate research attempts) and NVD had not yet indexed a CVSS record for this CVE as of the second corroboration pass (NVD CVE 2.0 API returned zero results, response timestamped 2026-08-02T03:07:10Z).

The reconstructed attack chain across all five independent technical writeups reviewed is consistent: (1) a malicious VM tenant crafts a specialized VIRTIO-Net message payload; (2) the message triggers a memory-manipulation defect in the VIRTIO-Net component's input handling; (3) arbitrary attacker-controlled data is written to unintended memory locations (the write-what-where primitive); (4) this can be leveraged for attacker-controlled code execution within the VIRTIO-Net component's process/execution scope; (5) the CVSS scope change (S:C) reflects that impact is not confined to VIRTIO-Net but can reach the broader DPU/host-adjacent context.

The practical risk scenario, repeated across every source reviewed, is a multi-tenant cloud or virtualization host where a customer-controlled VM is intentionally given only minimal privileges: the VIRTIO-Net bug lets that low-trust tenant potentially break out of its expected privilege boundary and corrupt memory in the DPU/host-adjacent VIRTIO-Net scope, which is the classic setup for a guest-to-host escape in DPU-offloaded virtualization architectures (BlueField DPUs are specifically marketed for offloading networking, storage, and security functions from the host CPU into an isolated ARM-based control plane -- a compromise of that plane is high-value because it sits outside the traditional hypervisor security boundary, potentially bypassing host-based EDR/monitoring entirely and giving visibility into every tenant's network traffic transiting the shared DPU).

Affected releases span all VIRTIO-Net branches NVIDIA currently supports: GA before 25.10.6, LTS25 before 25.10.2, LTS24 before 24.10.50, and LTS23 at 1.7.21 and earlier (fixed in 23.10.23). NVIDIA credits internal discovery, reports no active exploitation and no public proof-of-concept as of the July 29, 2026 disclosure, and directs customers to the DOCA downloads portal for the fixed packages. The CVE-2026-65094 identifier itself replaces an earlier provisional assignment (CVE-2025-33209) referenced in at least one technical summary, consistent with NVIDIA's practice of renumbering CVEs during coordinated-disclosure tracking refinement. Cross-referencing the CISA Known Exploited Vulnerabilities catalog (version 2026.07.29, 1,656 entries) confirms CVE-2026-65094 is not listed, and it is likewise absent from NVD's CVE 2.0 API response at research time -- both consistent with a freshly patched, non-exploited vendor disclosure rather than an active-exploitation event.

Notably, this disclosure is not isolated: NVD indexes a near-identical, directly related prior disclosure -- CVE-2025-23351 (and its sibling CVE-2025-23350) -- published July 1, 2026, exactly four weeks before CVE-2026-65094, affecting the same NVIDIA ConnectX/BlueField product family. CVE-2025-23351 shares the IDENTICAL reconstructed CVSS 3.1 vector (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.0) and describes the same root-cause pattern: "a local user with virtual function (VF) access may cause a write out of bounds by crafted input" in the ConnectX/BlueField command interface (CWE-787, Out-of-bounds Write, a close sibling of CWE-123), with NVIDIA's own advisory noting that on ConnectX-8 devices additional security mitigations "limit exploitation" and that a successful exploit "would require an attacker to invest significant resources to bypass those security mechanisms." Taken together, these two disclosures four weeks apart indicate a recurring memory-safety weakness pattern across NVIDIA's DPU/SmartNIC command and paravirtualized-device interfaces (command interface and VIRTIO-Net respectively) through mid-2026, both reachable by a low-privileged local/VM tenant and both carrying the maximum CVSS 9.0 score for this exploitation class -- a pattern worth tracking for defenders operating BlueField/ConnectX fleets rather than treating CVE-2026-65094 as an isolated one-off.

## MITRE ATT&CK

- T1595 Active Scanning
- T1078 Valid Accounts
- T1203 Exploitation for Client Execution
- T1055 Process Injection
- T1542 Pre-OS Boot
- T1068 Exploitation for Privilege Escalation
- T1611 Escape to Host
- T1611 Escape to Host
- T1211 Exploitation for Stealth
- T1014 Rootkit
- T1040 Network Sniffing
- T1040 Network Sniffing
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1495 Firmware Corruption
- T1499 Endpoint Denial of Service

## Sources

- [NVIDIA BlueField Vulnerability Enables Code Execution Attacks](https://cybersecuritynews.com/nvidia-bluefield-vulnerability/)
- [NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0)](https://securityonline.info/nvidia-bluefield-cve-2026-65094/)
- [Critical NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages](https://cyberpress.org/critical-nvidia-bluefield-flaw/)
- [NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages](https://gbhackers.com/nvidia-bluefield-flaw/)
- [NVIDIA BlueField Vulnerability Enables Code Execution Attacks](https://teamwin.in/nvidia-bluefield-vulnerability-enables-code-execution-attacks/)
- [Security Bulletin: NVIDIA Networking BlueField and ConnectX (a_id/5815)](https://nvidia.custhelp.com/app/answers/detail/a_id/5815)
- [CISA Known Exploited Vulnerabilities Catalog (verified CVE-2026-65094 absent, v2026.07.29)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [NVD - CVE-2025-23351 (related ConnectX/BlueField command-interface out-of-bounds write, identical CVSS 9.0 vector, published 2026-07-01)](https://nvd.nist.gov/vuln/detail/CVE-2025-23351)
- [stack.watch - NVIDIA Security Vulnerabilities 2026 index (confirms bulletin a_id/5815 = "NVIDIA Networking Bluefield, ConnectX - July 2026")](https://stack.watch/product/nvidia/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1812
