GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver (Windows): improper input validation in DxgkDdiEscape lets a local user crash the node

CVSS 5.5CVE-2022-28188NVIDIA / GPU stack+1 more CVEscurated

Impact

A local user on a Windows GPU node can pass malformed input to the kernel mode layer's DxgkDdiEscape handler and take the node down. The vendor split this across 2 ids (CVE-2022-28188, CVE-2022-28190) for separate code paths in the same handler, but the advisory gives no way to tell them apart and the fix is the same for both. Only matters to you if you run Windows GPU nodes: VDI/DaaS session hosts, cloud-gaming fleets, Windows render or CAE farms.

Who can reach it

Local and unprivileged on a Windows GPU node, through the driver's private IOCTL / DxgkDdiEscape path. Any interactive or RDP/Citrix session with a GPU handle can call it, so on a multi-session VDI host every logged-in user is in range.

What to do

Install the fixed Windows display driver from NVIDIA bulletin 5353 once; it covers both ids. Cost: a Windows display-driver replacement reboots the node, so drain sessions first. Linux-only fleets can skip this entirely.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2022-28190

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.