GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Out-of-bounds read or write in the kernel-mode

CVE-2021-1090NVIDIA / GPU stackcurated

Impact

Out-of-bounds read or write in the kernel-mode layer's control-call handler on both Windows and Linux. Unprivileged local code corrupts kernel memory or crashes the node; Gentoo shipped it as a security update.

Who can reach it

Any local user or GPU container with access to the NVIDIA device nodes.

What to do

Install the fixed GPU Display Driver branch on both Windows and Linux nodes. The kernel component (nvlddmkm.sys / nvidia.ko) cannot be hot-swapped under load, so this is a node drain and reboot per host; restart the container runtime afterwards so mounted driver libraries match the kernel module. No VBIOS or BMC flash.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.