关键漏洞信息 CVE ID: CVE-2025-23257 发布日期: 2025-09-04 更新日期: 2025-09-04 CNA: NVIDIA Corporation 描述 NVIDIA DOCA contains a vulnerability in the collectx-cxapidev Debian package that could allow an actor with low privileges to escalate privileges. A successful exploit of this vulnerability might lead to escalation of privileges. CWE CWE-732: Incorrect Permission Assignment for Critical Resource CVSS 评分: 7.3 严重性: HIGH 版本: 3.1 向量字符串: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H 产品状态 供应商: NVIDIA 产品: NVIDIA DOCA with collectx-cxapidev 平台: Linux - Debian based 2.9, 2.10 受影响版本: - All 2.9 versions prior to 2.9.3 - All 2.10 versions 参考链接 https://nvd.nist.gov/vuln/detail/CVE-2025-23257 https://www.cve.org/CVERecord?id=CVE-2025-23257 https://nvidia.custhelp.com/app/answers/detail/a_id/5655