GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver service host component: The service host can skip its integrity check on application

CVE-2020-5964NVIDIA / GPU stackcurated

Impact

The service host can skip its integrity check on application resources, so a local attacker who swaps a resource gets code execution in a privileged NVIDIA service.

Who can reach it

Local user able to write the resources the service loads.

What to do

Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.