GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Any local account on a Windows GPU host can call the driver's escape

CVE-2018-6247NVIDIA / GPU stackcurated

Impact

Any local account on a Windows GPU host can call the driver's escape path and hit a NULL dereference. Best case the box bugchecks and you lose every job on it; NVIDIA also rates privilege escalation as possible, which on a kernel driver means SYSTEM.

Who can reach it

Any local user or service account on the host, including anything running inside a Windows container that has the GPU mapped in.

What to do

Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.