Lucene search

K
cve[email protected]CVE-2016-7389
HistoryNov 08, 2016 - 8:59 p.m.

CVE-2016-7389

2016-11-0820:59:15
CWE-264
web.nvd.nist.gov
32
nvidia
gpu
display driver
linux
vulnerability
kernel
privilege escalation
cve-2016-7389

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.

Affected configurations

NVD
Node
nvidiagpu_driverMatch304.79
OR
nvidiagpu_driverMatch340.52
OR
nvidiagpu_driverMatch361.91
OR
nvidiagpu_driverMatch365.19
OR
nvidiagpu_driverMatch368.81
AND
linuxlinux_kernel
VendorProductVersionCPE
nvidiagpu_driver340.52cpe:/a:nvidia:gpu_driver:340.52:::
nvidiagpu_driver368.81cpe:/a:nvidia:gpu_driver:368.81:::
nvidiagpu_driver361.91cpe:/a:nvidia:gpu_driver:361.91:::
nvidiagpu_driver365.19cpe:/a:nvidia:gpu_driver:365.19:::
nvidiagpu_driver304.79cpe:/a:nvidia:gpu_driver:304.79:::

CNA Affected

[
  {
    "product": "Quadro, NVS, GeForce, and Tesla (all versions)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Quadro, NVS, GeForce, and Tesla (all versions)"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%