NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel read/write from an unprivileged escape call
Impact
Out-of-bounds kernel read/write from an unprivileged escape call - a length value is trusted that should not be. This is the shape that turns into a full SYSTEM escalation with enough effort, and a bugcheck with none.
Who can reach it
Any local user on the host with access to the GPU device, including low-privilege service accounts.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.
References
Related entries
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Same class as the other early-2018 escape bugs: an unprivilegedCVE-2018-6250 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A local user gets elevated enough to rewrite display configurationCVE-2021-1051 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): The context-creation DDI uses an untrusted array indexCVE-2019-5666 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the page-table DDI handler, reachable locallyCVE-2019-5667 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the virtual command submission handlerCVE-2019-5668 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel buffer access through the escape handlerCVE-2019-5669 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.