GPU Display Driver: Local privesc to host root (use-after-free)
CVE-2024-0091NVIDIA / GPU stackcurated
Impact
Local privesc to host root (use-after-free)
Who can reach it
Any tenant with a container
What to do
Driver upgrade; drain + reboot node
Fleet impact
How widespread
Universal - same driver
Cost to remediate
node-reboot
Why it hits the whole fleet
Untrusted-pointer dereference via a driver API call from a low-privileged tenant process, giving DoS / info disclosure / tampering on a shared host
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.