Lucene search

K
cveNvidiaCVE-2022-42254
HistoryDec 30, 2022 - 11:15 p.m.

CVE-2022-42254

2022-12-3023:15:10
CWE-129
CWE-125
nvidia
web.nvd.nist.gov
55
nvidia
gpu
display driver
linux
vulnerability
cve-2022-42254
kernel mode layer
nvidia.ko
out-of-bounds array access
denial of service
data tampering
information disclosure

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

13.0%

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.

Affected configurations

Nvd
Node
citrixhypervisorMatch-
OR
linuxlinux_kernelMatch-
OR
redhatenterprise_linux_kernel-based_virtual_machineMatch-
OR
vmwarevsphereMatch-
AND
nvidiavirtual_gpuRange<11.11
OR
nvidiavirtual_gpuRange12.013.6
OR
nvidiavirtual_gpuRange14.014.4
Node
linuxlinux_kernelMatch-
AND
nvidiacloud_gamingRange<525.60.11
Node
citrixhypervisorMatch-
OR
redhatenterprise_linux_kernel-based_virtual_machineMatch-
AND
nvidiacloud_gamingRange<525.60.12
Node
nvidiageforceMatch-
OR
nvidianvsMatch-
OR
nvidiaquadroMatch-
OR
nvidiartxMatch-
OR
nvidiateslaMatch-
AND
nvidiagpu_display_driverRange470470.161.03linux
OR
nvidiagpu_display_driverRange510510.108.03linux
OR
nvidiagpu_display_driverRange515515.86.01linux
VendorProductVersionCPE
citrixhypervisor-cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
redhatenterprise_linux_kernel-based_virtual_machine-cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
vmwarevsphere-cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
nvidiavirtual_gpu*cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
nvidiacloud_gaming*cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
nvidiageforce-cpe:2.3:a:nvidia:geforce:-:*:*:*:*:*:*:*
nvidianvs-cpe:2.3:a:nvidia:nvs:-:*:*:*:*:*:*:*
nvidiaquadro-cpe:2.3:a:nvidia:quadro:-:*:*:*:*:*:*:*
nvidiartx-cpe:2.3:a:nvidia:rtx:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "vendor": "NVIDIA",
    "product": "vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager)",
    "versions": [
      {
        "version": "All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

13.0%