Lucene search

K
cve[email protected]CVE-2021-1056
HistoryJan 08, 2021 - 1:15 a.m.

CVE-2021-1056

2021-01-0801:15:14
CWE-276
web.nvd.nist.gov
97
1
nvidia
gpu
display driver
linux
kernel
vulnerability
denial of service
information disclosure

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:N/A:P

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.

Affected configurations

NVD
Node
nvidiagpu_driverRange390390.141
OR
nvidiagpu_driverRange450450.102.04
OR
nvidiagpu_driverRange460460.32.03
AND
linuxlinux_kernelMatch-
Node
debiandebian_linuxMatch9.0

CNA Affected

[
  {
    "vendor": "NVIDIA",
    "product": "NVIDIA GPU Display Driver",
    "versions": [
      {
        "version": "All",
        "status": "affected"
      }
    ]
  }
]

Social References

More

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:N/A:P

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%