NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime): MULTI-TENANT ISOLATION: a crafted shader
Impact
MULTI-TENANT ISOLATION: a crafted shader reads out of bounds on an input texture array and gets code execution in the driver. VMware shipped its own advisory for this (VMSA-2019-0012) because in a virtualised graphics setup the shader comes from inside a guest VM - so this is a guest-to-host code execution path on a shared GPU host, which is why it carries a CVSS of 10.0. On a GPU cloud running vSGA/vGPU-adjacent graphics, one tenant's shader compromises the hypervisor host and therefore every other tenant on it.
Who can reach it
Anyone who can submit a shader to the host GPU: a tenant VM, a remote graphics session, or a local process. In the virtualised case, an unprivileged user inside any guest.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved. If you run VMware ESXi with virtualised graphics, also apply the fix VMware ships in VMSA-2019-0012 - the hypervisor-side package is separate from the in-guest driver, and both matter.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.