GPU Display Driver: Local privesc to host root (OOB write)
CVSS 7.8CVE-2024-0090NVIDIA / GPU stackcurated
Impact
Local privesc to host root (OOB write)
Who can reach it
Any tenant with a container
What to do
Driver upgrade; drain + reboot node
Fleet impact
How widespread
Universal - Windows and Linux driver, all datacenter SKUs
Cost to remediate
node-reboot (driver replacement)
Why it hits the whole fleet
Out-of-bounds write reachable from an unprivileged local user through the driver API: any tenant process on a GPU node can attempt host code execution
References
Related entries
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2024-0091 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (buffer over-read in driver)CVE-2024-0107 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (insufficient access control)CVE-2025-23244 · GPU Display DriverHigh
- GPU Display Driver: Local privesc via file permissionsCVE-2025-23276 · GPU Display DriverHigh
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2025-33217 · GPU Display DriverHigh
- GPU Display Driver: Kernel mode layer integer overflows allow local privilege escalationCVE-2025-33218 · GPU Display DriverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.