GPU Display Driver (GeForce/RTX/Quadro/Tesla/vGPU): Info disclosure + DoS (OOB read in kernel driver)
CVSS 7.1CVE-2023-0180NVIDIA / GPU stackcurated
Impact
Info disclosure + DoS (OOB read in kernel driver)
Who can reach it
Any tenant with GPU device access (local, unprivileged)
What to do
Upgrade driver to the Jan-2023 branch; drain + reboot node (kernel module reload evicts all GPU workloads)
References
Related entries
- GPU Display Driver: Local privesc / data tampering (missing access control)CVE-2023-0181 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (kernel buffer overflow)CVE-2023-0183 · GPU Display DriverHigh
- GPU Display Driver: Local privesc / data tampering (OOB write)CVE-2023-0191 · GPU Display DriverHigh
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An unprivileged user triggers an integer overflowCVE-2023-25516 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): The vGPU plugin lets a guest OS controlCVE-2023-25517 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- Jetson AGX Xavier / Xavier NX: Arbitrary memory R/W (PCIe controller without IOMMU)CVE-2023-25518 · Jetson AGX Xavier / Xavier NXHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.