NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime): A crafted shader reads out of bounds on an
Impact
A crafted shader reads out of bounds on an input texture array and gets code execution in the driver. VMware shipped its own advisory for this (VMSA-2019-0012) because in a virtualised graphics setup the shader comes from inside a guest VM - so this is a guest-to-host code execution path on a shared GPU host, which is why it carries a CVSS of 10.0. On a GPU cloud running vSGA/vGPU-adjacent graphics, one tenant's shader compromises the hypervisor host and therefore every other tenant on it.
Who can reach it
Anyone who can submit a shader to the host GPU: a tenant VM, a remote graphics session, or a local process. In the virtualised case, an unprivileged user inside any guest.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved. If you run VMware ESXi with virtualised graphics, also apply the fix VMware ships in VMSA-2019-0012 - the hypervisor-side package is separate from the in-guest driver, and both matter.
References
Related entries
- NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime): A crafted shader overruns a shader-localCVE-2019-5685 · NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime)Critical
- DGX A100 BMC: Full BMC compromise (heap buffer overflow) — worst-case out-of-band takeoverCVE-2023-31029 · DGX A100 BMCCritical
- Univa Grid Engine (execd spooling with Docker jobs on root_squash): In the specific combination of Docker-based jobsCVE-2018-20871 · Univa Grid Engine (execd spooling with Docker jobs on root_squash)Critical
- RISC-V ISA (MTVEC register) as used in NVIDIA GPU microcontrollers: A documented ambiguity in the RISC-V specificationCVE-2021-1104 · RISC-V ISA (MTVEC register) as used in NVIDIA GPU microcontrollersCritical
- DGX A100 BMC: unauthenticated stack overflow in the host KVM daemon leads to RCECVE-2023-31024 · DGX A100 BMCCritical
- Base Command Manager (CMDaemon): Unauthenticated RCE on the cluster managerCVE-2024-0138 · Base Command Manager (CMDaemon)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.