GPU Display Driver: Local privesc to host root (OOB write)
CVE-2024-0090NVIDIA / GPU stackcurated
Impact
Local privesc to host root (OOB write)
Who can reach it
Any tenant with a container
What to do
Driver upgrade; drain + reboot node
Fleet impact
How widespread
Universal - Windows and Linux driver, all datacenter SKUs
Cost to remediate
node-reboot (driver replacement)
Why it hits the whole fleet
Out-of-bounds write reachable from an unprivileged local user through the driver API: any tenant process on a GPU node can attempt host code execution
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.