CVE-2011-0636: Infoleak
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0636?
CVE-2011-0636 is considered a medium severity vulnerability due to its potential for local users to read sensitive memory.
How do I fix CVE-2011-0636?
To fix CVE-2011-0636, upgrade to a later version of the NVIDIA CUDA Toolkit that ensures proper initialization of pinned memory.
Who is affected by CVE-2011-0636?
CVE-2011-0636 affects users of the NVIDIA CUDA Toolkit version 3.2 and possibly other versions on Linux.
What types of memory are exposed in CVE-2011-0636?
CVE-2011-0636 allows local users to read potentially sensitive memory, including file fragments during read or write operations.
Is CVE-2011-0636 applicable to all NVIDIA CUDA Toolkit versions?
No, CVE-2011-0636 specifically affects the NVIDIA CUDA Toolkit version 3.2 and possibly other unspecified versions.