CVE-2026-24263: Null Pointer Dereference
Published Aug 25, 2026
·Updated
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Affected Software
1 affected component
Nvidia DGX Spark
Event History
Aug 25, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires a privileged attacker with local access. The CVSS vector indicates high privileges are required and no user interaction is needed.
2
What impact could successful exploitation have?
A successful exploit may enable code execution, privilege escalation, denial of service, information disclosure, and data tampering. The vulnerability is in system firmware and is caused by a NULL pointer dereference.