First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Display Driver | >=390<390.157 | |
Nvidia Gpu Display Driver | >=470<470.161.03 | |
Nvidia Gpu Display Driver | >=510<510.108.03 | |
Nvidia Gpu Display Driver | >=515<515.86.01 | |
Nvidia Gpu Display Driver | >=525<525.60.11 | |
Nvidia Geforce | ||
Nvidia Nvs | ||
Nvidia Quadro | ||
Nvidia Rtx | ||
Nvidia Gpu Display Driver | >=450<450.216.04 | |
Nvidia Tesla | ||
Nvidia Cloud Gaming | <525.60.12 | |
Citrix Hypervisor | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
NVIDIA Virtual GPU | <11.11 | |
NVIDIA Virtual GPU | >=12.0<13.6 | |
NVIDIA Virtual GPU | >=14.0<14.4 | |
Linux Linux kernel | ||
VMware vSphere | ||
Nvidia Cloud Gaming | <525.60.11 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34674 is a vulnerability in the NVIDIA GPU Display Driver for Linux that can lead to undefined behavior or an information leak.
The NVIDIA GPU Display Driver for Linux versions 390 to 525.60.11 are affected by CVE-2022-34674.
CVE-2022-34674 has a severity rating of 6.8 (medium).
To fix CVE-2022-34674, update your NVIDIA GPU Display Driver for Linux to a version higher than 525.60.11.
More information about CVE-2022-34674 can be found at the following references: [link1](https://lists.debian.org/debian-lts-announce/2023/05/msg00010.html), [link2](https://nvidia.custhelp.com/app/answers/detail/a_id/5415), [link3](https://security.gentoo.org/glsa/202310-02).