CVE-2018-6260: Infoleak
Last updated 25 August 2025
Other sources
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote attack vector.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6260?
CVE-2018-6260 is a vulnerability in the NVIDIA graphics driver that allows access to application data processed on the GPU through a side channel exposed by the GPU performance counters.
Is CVE-2018-6260 a remote attack vector?
No, CVE-2018-6260 requires local user access and is not a network or remote attack vector.
Which software versions are affected by the CVE-2018-6260 vulnerability?
The NVIDIA graphics driver versions 390.116, 390.116-0ubuntu0.18.04.1, 390.116-0ubuntu0.18.10.1, 418.226.00-3, 470.199.02-1, 525.125.06-1~deb12u1, 525.125.06-2, 340.108-3~deb10u1, 340.108-20, 390.154-1~deb10u1, 390.157-1~deb10u1, 390.157-1~deb11u1, and 390.157-5 are affected by the CVE-2018-6260 vulnerability.
Is there a severity rating for CVE-2018-6260?
Yes, CVE-2018-6260 has a severity rating of 5.5 (medium).
How can I fix the CVE-2018-6260 vulnerability?
To fix the CVE-2018-6260 vulnerability, update your NVIDIA graphics driver to version 390.116 or apply the relevant security patches provided by your operating system.