First published: Tue May 17 2022(Updated: )
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | >=11.0<11.8 | |
NVIDIA Virtual GPU | >=13.0<13.3 | |
NVIDIA Virtual GPU | =14.0 | |
Linux Linux kernel | ||
Microsoft Windows | ||
Nvidia Gpu Display Driver | ||
Nvidia Gpu Display Driver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28181 is critical.
CVE-2022-28181 affects NVIDIA Virtual GPU with versions between 11.0 and 11.8, versions between 13.0 and 13.3, and version 14.0.
Yes, an unprivileged regular user on the network can exploit CVE-2022-28181.
The impact of CVE-2022-28181 includes potential code execution, denial of service, escalation of privileges, and information disclosure.
You can find more information about CVE-2022-28181 at the following references: [link1](https://nvidia.custhelp.com/app/answers/detail/a_id/5353) and [link2](https://security.gentoo.org/glsa/202310-02).