CVE-2022-42255
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.
Affected (5)
Products: Nvidia: Virtual Gpu, Cloud Gaming
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.11 |
| Running on/with | Platform Versions |
|---|---|
Vmware Vsphere | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 525.60.11 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 525.60.12 |
| Running on/with | Platform Versions |
|---|---|
Citrix Hypervisor | All versions |
Redhat Enterprise Linux Kernel Based Virtual Machine | All versions |
Related CWEs
CWE-129
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.