SB2021080806 - Privilege escalation in NVIDIA DCGM
Published: August 8, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Code Injection (CVE-ID: CVE-2021-34398)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root. A local user can inject and execute arbitrary code on the system.
Remediation
Install update from vendor's website.