CVE-2026-65083: Critical severity Nvidia OpenShell for Linux vulnerability
Published Aug 25, 2026
·Updated
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
Affected Software
3 affected components
Nvidia OpenShell for Linux
All of the following
Nvidia OpenShell<=0.0.33
Linux Linux kernel
Event History
Aug 25, 2026
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges and can exploit the issue over the network. The attack has low complexity and does not require user interaction.
2
Can exploitation affect components outside the vulnerable sandbox provisioning API's security scope?
Yes. The CVSS vector indicates a changed scope, meaning a successful exploit may affect resources beyond the authority of the vulnerable component.