First published: Fri Nov 18 2022(Updated: )
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to a system crash or a leak of internal kernel information.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Display Driver | >=471.11<473.81 | |
Nvidia Gpu Display Driver | >=516.25<516.94 | |
Nvidia Geforce | ||
NVIDIA Virtual GPU | >=11.0<11.8 | |
NVIDIA Virtual GPU | >=13.0<13.3 | |
NVIDIA Virtual GPU | =14.0 | |
Microsoft Windows | ||
Nvidia Cloud Gaming Guest | <516.94 | |
Nvidia Studio | ||
Nvidia Gpu Display Driver | >=511.09<513.46 | |
Nvidia Gpu Display Driver | >=451.48<453.64 | |
Nvidia Gpu Display Driver | >=471.11<472.81 | |
Nvidia Tesla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31612 is a vulnerability in the NVIDIA GPU Display Driver for Windows that allows a local user to cause an out-of-bounds read and potentially crash the system or leak internal kernel information.
The affected software versions include Nvidia GPU Display Driver for Windows versions 471.11 to 473.81 and versions 516.25 to 516.94.
No, Nvidia Geforce is not affected by CVE-2022-31612.
CVE-2022-31612 has a severity rating of 7.1, which is considered high.
To fix CVE-2022-31612, update the Nvidia GPU Display Driver for Windows to a version that is not vulnerable.