Skip to main content

Mid-2024 NVIDIA GPU Display Driver Bulletins: Out-of-Bounds Writes and Reads Across the Driver Stack

BulletinKey CVEsDisclosed
June 2024CVE-2024-0090, CVE-2024-0089, CVE-2024-0091, CVE-2024-0093June 2024
July 2024CVE-2024-0107 and additional display driver CVEsJuly 2024

For executives

NVIDIA published two GPU display driver security bulletins in mid-2024, in June and July. The June bulletin contained multiple CVSS 7.8 vulnerabilities — out-of-bounds writes and buffer overflows that allow local attackers to achieve code execution, privilege escalation, information disclosure, and data tampering. The July bulletin added further display driver vulnerabilities including an out-of-bounds read in the Windows driver's user mode layer.

June 2024 bulletin: out-of-bounds writes in the display driver

CVE-2024-0090 (CVSS 7.8), CVE-2024-0089 (CVSS 7.8), and CVE-2024-0091 (CVSS 7.8) are all in the same vulnerability class but exploit different code paths within the driver's buffer handling — meaning the patch for one does not address the others.

The June 2024 bulletin also contained vGPU-specific vulnerabilities. CVE-2024-0084 affects NVIDIA vGPU software for Linux where the guest OS could execute privileged operations on the Virtual GPU Manager.

July 2024 bulletin: out-of-bounds read in the Windows user mode layer

CVE-2024-0107 (CVSS 7.8) is an out-of-bounds read in the NVIDIA GPU display driver for Windows, in the user mode layer. An unprivileged regular user can trigger the condition. In multi-user or multi-workload GPU environments, adjacent memory is not guaranteed to be the attacker's own.

Patch

June 2024: Windows driver 556.12 or later. July 2024: driver versions listed in the NVIDIA July 2024 security bulletin.