GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko): An out-of-bounds read

CVE-2022-28183NVIDIA / GPU stackcurated

Impact

An out-of-bounds read in the kernel mode layer leaks kernel memory to an unprivileged local user. Both the Windows and Linux datacenter drivers are affected, so a mixed fleet needs two separate rollouts.

Who can reach it

Local and unprivileged on either OS. On Linux it is reachable from any GPU container via /dev/nvidia*; on Windows from any session holding a GPU handle.

What to do

Upgrade both the Linux and the Windows datacenter driver branches listed in bulletin 5353. Cost: Linux needs a drain and nvidia.ko reload per node; Windows needs a reboot per node. Two change windows unless your fleet is homogeneous.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.