NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A local user gets elevated enough to rewrite display configuration
Impact
A local user gets elevated enough to rewrite display configuration through the escape handler, taking the display subsystem out. On a headless compute node the display path matters less, but the underlying escape-handler privilege gap is the same one that produces worse bugs.
Who can reach it
Any local user with GPU device access on a Windows host.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.
References
Related entries
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): The context-creation DDI uses an untrusted array indexCVE-2019-5666 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the page-table DDI handler, reachable locallyCVE-2019-5667 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): NULL dereference in the virtual command submission handlerCVE-2019-5668 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel buffer access through the escape handlerCVE-2019-5669 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Same escape-handler length bug but with information disclosureCVE-2019-5670 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Unsynchronized shared state (static variables across threads)CVE-2019-5675 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.