GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver kernel mode layer: null-pointer dereferences allow local denial of service

CVSS 6.5CVE-2022-34665NVIDIA / GPU stack+1 more CVEscurated

Impact

An unprivileged local account can crash the node via a null-pointer dereference in the kernel mode layer (nvlddmkm.sys on Windows, nvidia.ko on Linux). NVIDIA split this across 2 ids in bulletin 5383, one per affected code path; both are fixed by the same driver update, and both Windows and Linux datacenter drivers are affected, so a mixed fleet still needs two rollouts.

Who can reach it

Local and unprivileged on either OS. On Linux it is reachable from any GPU container via /dev/nvidia*; on Windows from any session holding a GPU handle.

What to do

Upgrade to the fixed Linux and Windows datacenter driver branches listed in NVIDIA bulletin 5383. One upgrade closes both ids. Cost: Linux needs a drain and nvidia.ko reload per node; Windows needs a reboot per node - two change windows unless your fleet is homogeneous.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2022-34666

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.