NVIDIA DCGM - nv-hostengine: A network-reachable caller drives nv-hostengine into an unhandled error condition
Impact
A network-reachable caller drives nv-hostengine into an unhandled error condition, reaching limited code execution and privilege escalation. DCGM runs as root on every GPU node and holds the fleet's telemetry, so it is a high-value target sitting on an open port.
Who can reach it
Network, with low privileges. nv-hostengine listens on TCP 5555 by default and many operators leave it bound beyond localhost so a central collector can scrape it - that binding is the exposure.
What to do
Update DCGM per bulletin 5328 and restart nv-hostengine. Cost: restarting the host engine briefly interrupts telemetry but does not touch running GPU jobs - no drain needed. While you are there, bind nv-hostengine to localhost and scrape via a local exporter instead of exposing 5555.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.