NVIDIA DCGM - nv-hostengine: A heap-based buffer overflow reachable through the bound socket gives denial of service
CVSS 8.4CVE-2023-0208NVIDIA / GPU stackcurated
Impact
A heap-based buffer overflow reachable through the bound socket gives denial of service and data tampering with a changed CVSS scope, against a root-privileged daemon on every GPU node.
Who can reach it
Local or network depending on how you bound the socket. If nv-hostengine is listening on a routable interface, any host on that network can reach it.
What to do
Update DCGM per bulletin 5453 and restart nv-hostengine. Cost: telemetry gap of seconds, no GPU job impact, no drain. Restrict the listening socket to localhost as a standing control.
References
Related entries
- NVIDIA DCGM - nv-hostengine: A network-reachable caller drives nv-hostengine into an unhandled error conditionCVE-2022-21820 · NVIDIA DCGM - nv-hostengineMedium
- NVIDIA Isaac Lab (Isaac Sim): SB3 configuration parsing reaches code execution with no privileges and no userCVE-2025-23356 · NVIDIA Isaac Lab (Isaac Sim)High
- NVIDIA Resiliency Extension: Predictable log-file names in the log-aggregation path let an attacker pre-createCVE-2025-33225 · NVIDIA Resiliency ExtensionHigh
- TensorRT-LLM: RCE via unsafe deserializationCVE-2026-24233 · TensorRT-LLMHigh
- DGX H100 BMC: Privesc + code execution (web UI input validation)CVE-2023-25533 · DGX H100 BMCHigh
- DGX H100 BMC (REST): Code execution + privescCVE-2023-31009 · DGX H100 BMC (REST)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.