Database/Control plane, storage & DevOps
Intel Data Center GPU Flex Series - Windows driver: Improper buffer restrictions in the Flex Series Windows driver let
CVSS 7.3CVE-2024-36292Control plane, storage & DevOpscurated
Impact
Improper buffer restrictions in the Flex Series Windows driver let an authenticated user knock the GPU out. Flex Series is the media/VDI-oriented datacenter part, so the affected hosts are typically multi-session - meaning any logged-in user, not just an administrator.
Who can reach it
Local, authenticated, on a Windows host running the Flex Series driver before 31.0.101.4314.
What to do
Update the Flex Series Windows driver to 31.0.101.4314 or later. Cost: Windows driver replacement means a node reboot; drain sessions first.
References
Related entries
- Intel Data Center GPU Flex Series - Windows driver: A further improper access control in the Flex Series Windows driverCVE-2024-45333 · Intel Data Center GPU Flex Series - Windows driverHigh
- AMD Optimizing CPU Libraries (AOCL) - DLL hijacking: A DLL search-order hijack in AOCL lets an attacker getCVE-2024-36339 · AMD Optimizing CPU Libraries (AOCL) - DLL hijackingHigh
- Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacksCVE-2024-37130 · Dell OpenManage Server Administrator (XSL hijacking local privilege escalation)High
- Nx @nx/docker: config-controlled shell injection in release commands executes code in the release jobCVE-2026-104859 · Nx @nx/docker release pipeline (repositoryName / registryUrl shell interpolation)High
- ansible.posix authorized_key: a symlink under a user's ~/.ssh redirects a root chown to any pathCVE-2026-11837 · ansible.posix collection - authorized_key module (keyfile() ownership handling)High
- GitLab EE: developer-role user can run arbitrary commands in CI via attacker-controlled agent configCVE-2026-18252 · GitLab EE CI (Claude agent processing configuration from a user-controlled source)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.