GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko): The driver parses unexpected

CVE-2023-25515NVIDIA / GPU stackcurated

Impact

The driver parses unexpected untrusted data, reaching code execution, privilege escalation and information disclosure from an unprivileged local account on either OS. Both the Windows and Linux datacenter drivers are affected, so a mixed fleet needs two separate rollouts.

Who can reach it

Local and unprivileged on either OS. On Linux it is reachable from any GPU container via /dev/nvidia*; on Windows from any session holding a GPU handle.

What to do

Upgrade both the Linux and the Windows datacenter driver branches listed in bulletin 5468. Cost: Linux needs a drain and nvidia.ko reload per node; Windows needs a reboot per node. Two change windows unless your fleet is homogeneous.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.