GPU Display Driver: Local privesc to host root (use-after-free)
CVSS 7.8CVE-2024-0091NVIDIA / GPU stackcurated
Impact
Local privesc to host root (use-after-free)
Who can reach it
Any tenant with a container
What to do
Driver upgrade; drain + reboot node
Fleet impact
How widespread
Universal - same driver
Cost to remediate
node-reboot
Why it hits the whole fleet
Untrusted-pointer dereference via a driver API call from a low-privileged tenant process, giving DoS / info disclosure / tampering on a shared host
References
Related entries
- GPU Display Driver: Local privesc (buffer over-read in driver)CVE-2024-0107 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (insufficient access control)CVE-2025-23244 · GPU Display DriverHigh
- GPU Display Driver: Local privesc via file permissionsCVE-2025-23276 · GPU Display DriverHigh
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2025-33217 · GPU Display DriverHigh
- GPU Display Driver: Kernel mode layer integer overflows allow local privilege escalationCVE-2025-33218 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (insufficient permission checks)CVE-2026-24190 · GPU Display DriverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.