NVIDIA GPU Display Driver (Windows user mode layer): out-of-bounds reads reachable by an unprivileged local user
Impact
An unprivileged local user on a Windows GPU node can trigger an out-of-bounds read in the display driver's user mode layer, potentially reaching information disclosure, memory corruption, code execution and privilege escalation; in virtualized desktop setups the trigger can arrive through a remoted graphics session. NVIDIA split this single class of flaw across 5 ids (CVE-2024-0117 through CVE-2024-0121, all CWE-125, all CVSS 7.8) in the October 2024 bulletin 5586. Only relevant if you run Windows GPU nodes: VDI/DaaS session hosts, cloud-gaming fleets, Windows render or CAE farms. Linux-only fleets are unaffected.
Who can reach it
Local and unprivileged on a Windows GPU node, through the driver's private IOCTL / DxgkDdiEscape path. Any interactive or RDP/Citrix session with a GPU handle can call it, so on a multi-session VDI host every logged-in user is in range.
What to do
Install the fixed Windows display driver from NVIDIA bulletin 5586 (October 2024) once; that single update closes all five ids. Cost: a Windows display-driver replacement reboots the node, so drain sessions first. Linux-only fleets can skip this entirely.
Also covers 4 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU Display Driver - Windows user mode layer: The user mode driver layer lets an unprivileged user readCVE-2022-34669 · NVIDIA GPU Display Driver - Windows user mode layerHigh
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A tenant who has compromised their ownCVE-2024-0127 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- vGPU Manager: Guest-to-host escape via GPU firmware buffer overflowCVE-2024-0146 · vGPU ManagerHigh
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): A use-after-free in the amdgpuCVE-2024-26656 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2024-26699 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2024-26728 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.