GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU Display Driver (nvlddmkm.sys): The context-creation DDI uses an untrusted array index

CVE-2019-5666NVIDIA / GPU stackcurated

Impact

The context-creation DDI uses an untrusted array index without validating it. Unprivileged local code gets an out-of-bounds kernel access, which NVIDIA rates as escalation-capable.

Who can reach it

Any local user with GPU device access on the host.

What to do

Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.