First published: Tue Nov 08 2016(Updated: )
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000194 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU kernel driver | >=340<342.00 | |
NVIDIA GPU kernel driver | >=375<375.63 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7390 is considered a high severity vulnerability that can lead to potential escalation of privileges on affected NVIDIA GPU driver versions.
To fix CVE-2016-7390, update the NVIDIA Windows GPU Display Driver to version 342.00 or later, or version 375.63 or later.
CVE-2016-7390 affects NVIDIA Quadro, NVS, and GeForce products specifically using vulnerable driver versions prior to 342.00 and 375.63.
CVE-2016-7390 is caused by improper validation of a value passed from user mode to the NVIDIA driver in the kernel mode layer.
There are no known workarounds for CVE-2016-7390; updating the driver is the recommended mitigation.