NVIDIA License System - DLS virtual appliance: Installation scripts on the DLS appliance leave other users' credentials
CVSS 5.4CVE-2022-21818NVIDIA / GPU stackcurated
Impact
Installation scripts on the DLS appliance leave other users' credentials readable to any signed-in portal user, giving lateral privilege escalation inside your licensing infrastructure.
Who can reach it
Network, authenticated as any portal user. Anyone you gave a licensing-portal account to.
What to do
Patch the DLS appliance per bulletin 5319 and rotate every credential the appliance held - the patch does not undo the exposure. Cost: appliance restart; vGPU guests keep running on cached licences through a short DLS outage.
References
Related entries
- Triton Inference Server: Insufficient access-control granularityCVE-2024-0103 · Triton Inference ServerMedium
- Intel Gaudi / gaudi-container-runtime: A path-traversal bug in the container runtime shim that wires Gaudi devices intoCVE-2026-32677 · Intel Gaudi / gaudi-container-runtimeMedium
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Improper access control in the escape handler leaks informationCVE-2021-1055 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)Medium
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An off-by-one error in nvidia.ko permits data tamperingCVE-2022-34684 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)Medium
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An out-of-bounds array access in nvidia.ko givesCVE-2022-42254 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)Medium
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): A second out-of-bounds array access path in nvidia.koCVE-2022-42255 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.