# CVE-2025-33215

## Summary

- **CVE ID:** CVE-2025-33215
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
- **CWE:** CWE-823
- **Published:** Mar 24, 2026
- **Last Modified:** Mar 24, 2026

## Description

NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of storage to other VMs.

## Affected Products

- NVIDIA — SNAP-4 Container (All versions prior to SNAP-4.9.1 and SNAP-4.5.5)

## References

- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2025-33215)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2025-33215)
- [CNA](https://nvidia.custhelp.com/app/answers/detail/a_id/5744)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._