First published: Tue May 17 2022(Updated: )
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA vGPU Software | >=11.0<11.8 | |
NVIDIA vGPU Software | >=13.0<13.3 | |
NVIDIA vGPU Software | =14.0 | |
Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28185 is considered a critical vulnerability that can lead to denial of service and data tampering.
To fix CVE-2022-28185, you should update the NVIDIA GPU Display Driver to a version above the affected versions listed.
CVE-2022-28185 affects users of the NVIDIA vGPU Software versions between 11.0-11.8 and 13.0-13.3, as well as version 14.0.
The risks include potential system crashes due to denial of service and unauthorized data manipulation.
No, CVE-2022-28185 specifically affects the NVIDIA GPU Display Driver and does not impact the Linux kernel or Windows OS directly.