NVIDIA GPU Display Driver service host component: The service host can skip its integrity check on application
CVSS 7.8CVE-2020-5964NVIDIA / GPU stackcurated
Impact
The service host can skip its integrity check on application resources, so a local attacker who swaps a resource gets code execution in a privileged NVIDIA service.
Who can reach it
Local user able to write the resources the service loads.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.
References
Related entries
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the escape handlerCVE-2020-5966 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA vGPU Manager (vGPU plugin): The vGPU plugin fails to bound an indexed or pointer-based access, and NVIDIA callsCVE-2020-5968 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Out-of-bounds read in the vGPU plugin that NVIDIA rates as code-execution capable. ACVE-2020-5971 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A securely loaded system DLL then loads its own dependenciesCVE-2020-5980 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll): Crafted shader triggers an out-of-boundsCVE-2020-5981 · NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll)High
- NVIDIA vGPU Manager (vGPU plugin): Use-after-free while releasing resources in the vGPU plugin, rated code-executionCVE-2020-5984 · NVIDIA vGPU Manager (vGPU plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.