GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA DCGM - nv-hostengine: A heap-based buffer overflow reachable through the bound socket gives denial of service

CVE-2023-0208NVIDIA / GPU stackcurated

Impact

A heap-based buffer overflow reachable through the bound socket gives denial of service and data tampering with a changed CVSS scope, against a root-privileged daemon on every GPU node.

Who can reach it

Local or network depending on how you bound the socket. If nv-hostengine is listening on a routable interface, any host on that network can reach it.

What to do

Update DCGM per bulletin 5453 and restart nv-hostengine. Cost: telemetry gap of seconds, no GPU job impact, no drain. Restrict the listening socket to localhost as a standing control.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.