GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware microcontroller (Falcon): Debug mechanisms in the GPU's internal microcontroller are reachable with

CVE-2021-1088NVIDIA / GPU stackcurated

Impact

Debug mechanisms in the GPU's internal microcontroller are reachable with insufficient access control, leaking information from below the driver. The microcontroller sits underneath every context on the card, so what leaks is not bounded by process or VM. Applies across the datacenter line including DGX-1, DGX-2 and DGX Station A100.

Who can reach it

A user with elevated privileges on the host. In a bare-metal GPU-rental model that is the tenant themselves, which makes 'requires root' a much weaker precondition than it sounds.

What to do

NVIDIA shipped the fix in GPU firmware/microcode delivered with the R470 and R450 driver branches and, on some SKUs, in an updated VBIOS. On most datacenter parts the microcontroller image is loaded by the driver at GPU init, so a driver upgrade plus a node reboot applies it; check the bulletin's product table, because a subset of boards also needs an out-of-band VBIOS/InfoROM update, which is an offline per-node flash with the GPU idle. Either way the node has to be drained.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.