CVE-2015-5053: Critical severity nvidia gpu kernel driver vulnerability
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the followpfn kernel-mode API call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5053?
CVE-2015-5053 has a critical severity level due to potential privilege escalation and denial of service risks.
How do I fix CVE-2015-5053?
To mitigate CVE-2015-5053, users should update their NVIDIA GPU drivers to versions 346.87 or later for the R346 branch and 352.46 or later for the R352 branch.
Which versions are affected by CVE-2015-5053?
CVE-2015-5053 affects NVIDIA GPU Driver versions 346.16, 346.22, 346.35, 346.47, 346.59, 346.72, 346.82, 352.09, 352.21, and 352.41.
What types of attacks can CVE-2015-5053 facilitate?
CVE-2015-5053 can allow attackers to escalate privileges and potentially cause a denial of service by accessing unauthorized device IO memory.
Is CVE-2015-5053 applicable to Windows operating systems?
CVE-2015-5053 specifically affects Linux systems running the vulnerable versions of the NVIDIA GPU graphics driver.