Lucene search

K
cveNvidiaCVE-2022-42265
HistoryDec 30, 2022 - 11:15 p.m.

CVE-2022-42265

2022-12-3023:15:11
CWE-190
nvidia
web.nvd.nist.gov
51
nvidia
gpu
display
driver
linux
vulnerability
cve-2022-42265
integer overflow
information disclosure
data tampering
nvidia.ko
kernel mode

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

High

EPSS

0

Percentile

13.0%

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

Affected configurations

Nvd
Node
nvidiagpu_display_driverRange515515.86.01linux
AND
nvidiageforceMatch-
OR
nvidianvsMatch-
OR
nvidiaquadroMatch-
OR
nvidiartxMatch-
OR
nvidiateslaMatch-
VendorProductVersionCPE
nvidiagpu_display_driver*cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:linux:*:*
nvidiageforce-cpe:2.3:a:nvidia:geforce:-:*:*:*:*:*:*:*
nvidianvs-cpe:2.3:a:nvidia:nvs:-:*:*:*:*:*:*:*
nvidiaquadro-cpe:2.3:a:nvidia:quadro:-:*:*:*:*:*:*:*
nvidiartx-cpe:2.3:a:nvidia:rtx:-:*:*:*:*:*:*:*
nvidiatesla-cpe:2.3:a:nvidia:tesla:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "NVIDIA",
    "product": "NVIDIA GPU Display Driver for Linux",
    "versions": [
      {
        "version": "All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

High

EPSS

0

Percentile

13.0%