NVIDIA GPU Display Driver, inter-process communication APIs: Improper access control on the driver's IPC surface gives
Impact
Improper access control on the driver's IPC surface gives a local attacker code execution, a crash, or a read of data crossing that IPC. This one also shipped as an Ubuntu security update, so Linux compute nodes are in scope, not just Windows workstations.
Who can reach it
Any local user or container on the host that can reach the driver's IPC endpoints.
What to do
Install the fixed GPU Display Driver branch on both Windows and Linux nodes. The kernel component (nvlddmkm.sys / nvidia.ko) cannot be hot-swapped under load, so this is a node drain and reboot per host; restart the container runtime afterwards so mounted driver libraries match the kernel module. No VBIOS or BMC flash.
References
Related entries
- NVIDIA GPU Display Driver service host component: The service host can skip its integrity check on applicationCVE-2020-5964 · NVIDIA GPU Display Driver service host componentHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the escape handlerCVE-2020-5966 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA vGPU Manager (vGPU plugin): The vGPU plugin fails to bound an indexed or pointer-based access, and NVIDIA callsCVE-2020-5968 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Out-of-bounds read in the vGPU plugin that NVIDIA rates as code-execution capable. ACVE-2020-5971 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A securely loaded system DLL then loads its own dependenciesCVE-2020-5980 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll): Crafted shader triggers an out-of-boundsCVE-2020-5981 · NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.