NVIDIA GPU Display Driver, GPU firmware: An attacker-triggerable assert in GPU firmware aborts harder than it needs
Impact
An attacker-triggerable assert in GPU firmware aborts harder than it needs to, crashing the system. Firmware-level asserts are worth noting because the failure is below the driver: the recovery is a node reset, not a service restart. Debian and Gentoo shipped it as a security update.
Who can reach it
Any local user or GPU container able to drive the firmware into the asserting path.
What to do
Install the fixed GPU Display Driver branch on both Windows and Linux nodes. The kernel component (nvlddmkm.sys / nvidia.ko) cannot be hot-swapped under load, so this is a node drain and reboot per host; restart the container runtime afterwards so mounted driver libraries match the kernel module. No VBIOS or BMC flash.
References
Related entries
- NVIDIA vGPU Manager kernel module (nvidia.ko, host): The host vGPU kernel module dereferences an unvalidated user-spaceCVE-2021-1100 · NVIDIA vGPU Manager kernel module (nvidia.ko, host)Medium
- DGX servers BMC: Sensitive data exposure from BMCCVE-2022-42284 · DGX servers BMCMedium
- NVIDIA Run:ai: Improper restriction of communication channels lets an attacker on an adjacent network reachCVE-2025-33176 · NVIDIA Run:aiMedium
- TensorRT-LLM: DoS via large tensor allocationCVE-2026-24271 · TensorRT-LLMMedium
- TensorRT-LLM: DoS / memory corruption (insufficient tensor validation)CVE-2026-47470 · TensorRT-LLMMedium
- TensorRT-LLM: DoS via assertion failureCVE-2026-47475 · TensorRT-LLMMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.