First published: Tue Nov 13 2018(Updated: )
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote attack vector.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Driver | ||
ubuntu/nvidia-graphics-drivers-390 | <390.116-0ubuntu0.18.04.1 | 390.116-0ubuntu0.18.04.1 |
ubuntu/nvidia-graphics-drivers-390 | <390.116-0ubuntu0.18.10.1 | 390.116-0ubuntu0.18.10.1 |
ubuntu/nvidia-graphics-drivers-390 | <390.116 | 390.116 |
debian/nvidia-graphics-drivers | 470.256.02-2 535.183.01-1~deb12u1 535.183.06-1 | |
debian/nvidia-graphics-drivers-legacy-340xx | <=340.108-21 | |
debian/nvidia-graphics-drivers-legacy-390xx | 390.157-1~deb11u1 390.157-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6260 is a vulnerability in the NVIDIA graphics driver that allows access to application data processed on the GPU through a side channel exposed by the GPU performance counters.
No, CVE-2018-6260 requires local user access and is not a network or remote attack vector.
The NVIDIA graphics driver versions 390.116, 390.116-0ubuntu0.18.04.1, 390.116-0ubuntu0.18.10.1, 418.226.00-3, 470.199.02-1, 525.125.06-1~deb12u1, 525.125.06-2, 340.108-3~deb10u1, 340.108-20, 390.154-1~deb10u1, 390.157-1~deb10u1, 390.157-1~deb11u1, and 390.157-5 are affected by the CVE-2018-6260 vulnerability.
Yes, CVE-2018-6260 has a severity rating of 5.5 (medium).
To fix the CVE-2018-6260 vulnerability, update your NVIDIA graphics driver to version 390.116 or apply the relevant security patches provided by your operating system.