NVIDIA NVFlash / NVUFlash / GPUModeSwitch kernel driver (nvflash.sys, nvflsh32/64.sys): MULTI-TENANT ISOLATION
Impact
MULTI-TENANT ISOLATION: NVIDIA's signed flashing driver hands an administrator raw access to device memory and registers of arbitrary PCIe devices - including hardware NVIDIA does not own. That is a general-purpose physical-memory and device-register primitive wrapped in a legitimately signed driver, so it defeats driver signature enforcement and lets an admin (or malware that reached admin) reach across to the BMC, NICs, NVMe and other tenants' passthrough devices on the same host. Even on hosts that never flashed a GPU, its presence is a lasting bring-your-own-vulnerable-driver weapon.
Who can reach it
An authenticated administrator on the host, or any code that reached admin - which is exactly the boundary a signed kernel driver is supposed to hold.
What to do
Update NVFlash/NVUFlash to 5.588.0 or later and GPUModeSwitch to the 2019-11 build, and remove the old nvflash.sys / nvflsh32.sys / nvflsh64.sys drivers from every host they were ever installed on. These are flashing tools, not runtime components: the durable fix is to keep the signed vulnerable driver off production hosts entirely and add its hashes to your driver blocklist, since it is a bring-your-own-vulnerable-driver primitive independent of NVIDIA. Removing the driver needs a reboot; no GPU firmware flash.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.