First published: Thu Jul 22 2021(Updated: )
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=427.33<427.48 | |
NVIDIA GPU Display Driver | >=452.96<453.10 | |
NVIDIA GPU Display Driver | >=462.31<462.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1090 is classified as a critical vulnerability due to its potential to allow arbitrary memory access.
To fix CVE-2021-1090, update the NVIDIA GPU Display Driver to the latest version provided by NVIDIA.
CVE-2021-1090 affects specific versions of the NVIDIA GPU Display Driver, including those between 427.33 to 427.48, 452.96 to 453.10, and 462.31 to 462.96.
CVE-2021-1090 is a buffer overflow vulnerability in the kernel mode layer of the NVIDIA GPU Display Driver.
Yes, CVE-2021-1090 can potentially be exploited to execute arbitrary code, leading to remote exploitation.