CVE-2022-34677
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.
Affected (12)
Products: Nvidia: Gpu Display Driver, Cloud Gaming, Virtual Gpu · Debian: Debian Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 390 to 390.157 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Geforce | All versions |
Nvidia Nvs | All versions |
Nvidia Quadro | All versions |
Nvidia Rtx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 450 to 450.216.04 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Tesla | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 525.60.12 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.11 |
| Running on/with | Platform Versions |
|---|---|
Citrix Hypervisor | All versions |
Redhat Enterprise Linux Kernel Based Virtual Machine | All versions |
Vmware Vsphere | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 525.60.11 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Related CWEs
CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-681
Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
References (6)
Source: psirt@nvidia.com
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.