CVE-2023-25525: NVIDIA Cumulus Linux

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure.

Affected products

  • NVIDIA Cumulus Linux: before 5.6.0 (fixed in 5.6.0)

Published 2023-09-20. Last modified 2026-06-17.