NVIDIA DCGM - nv-hostengine: A heap-based buffer overflow reachable through the bound socket gives denial of service
CVE-2023-0208NVIDIA / GPU stackcurated
Impact
A heap-based buffer overflow reachable through the bound socket gives denial of service and data tampering with a changed CVSS scope, against a root-privileged daemon on every GPU node.
Who can reach it
Local or network depending on how you bound the socket. If nv-hostengine is listening on a routable interface, any host on that network can reach it.
What to do
Update DCGM per bulletin 5453 and restart nv-hostengine. Cost: telemetry gap of seconds, no GPU job impact, no drain. Restrict the listening socket to localhost as a standing control.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.