GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU Display Driver (nvlddmkm.sys): Out-of-bounds kernel read/write from an unprivileged escape call

CVE-2018-6248NVIDIA / GPU stackcurated

Impact

Out-of-bounds kernel read/write from an unprivileged escape call - a length value is trusted that should not be. This is the shape that turns into a full SYSTEM escalation with enough effort, and a bugcheck with none.

Who can reach it

Any local user on the host with access to the GPU device, including low-privilege service accounts.

What to do

Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.