CVE-2021-1056 is an improper access-control vulnerability affecting all versions of the NVIDIA GPU Display Driver for Linux. The kernel-mode component nvidia.ko does not completely honor operating-system file-system permissions intended to enforce GPU device-level isolation. This condition can result in denial of service or information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a proof-of-concept exploit for CVE-2021-1056, a vulnerability in NVIDIA's container runtime and GPU drivers that allows a user in a GPU-enabled container to gain access to all GPU devices on the host. The exploit is implemented as a Bash script (main.sh) that programmatically creates additional /dev/nvidia* device nodes inside the container, bypassing cgroup-based device isolation. The repository also includes a Python script (tf_distr_demo.py) to demonstrate distributed TensorFlow training across the newly accessible GPUs, and utility scripts for logging and GPU enumeration. The exploit requires the container to have the capability to create device nodes (MKNOD), and targets environments using nvidia-container-runtime with vulnerable NVIDIA drivers. No network endpoints are involved; the attack vector is local to the container environment. The repository is well-documented, with a QuickStart guide and detailed README explaining the vulnerability, exploitation steps, and mitigation strategies.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.