GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): NULL dereference in the kernel-mode layer reachable

CVE-2018-6249NVIDIA / GPU stackcurated

Impact

NULL dereference in the kernel-mode layer reachable from unprivileged code on Windows, Linux, FreeBSD and Solaris hosts. Loss of the node at minimum; NVIDIA leaves escalation on the table.

Who can reach it

Any local user with a handle on the GPU device node - which on Linux means anyone in the container that got /dev/nvidia*.

What to do

Install the fixed GPU Display Driver branch on both Windows and Linux nodes. The kernel component (nvlddmkm.sys / nvidia.ko) cannot be hot-swapped under load, so this is a node drain and reboot per host; restart the container runtime afterwards so mounted driver libraries match the kernel module. No VBIOS or BMC flash.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.