CVE-2022-31616
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information disclosure.
Affected (9)
Products: Nvidia: Virtual Gpu, Cloud Gaming Guest, Gpu Display Driver
Configuration A
| Running on/with | Platform Versions |
|---|---|
Nvidia Geforce | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.0 to 11.8 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 516.94 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 471.11 to 473.81 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Studio | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 451.48 to 453.64 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Tesla | All versions |
Related CWEs
CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (2)
Source: psirt@nvidia.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.