First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <11.11 | |
NVIDIA Virtual GPU | >=12.0<13.6 | |
NVIDIA Virtual GPU | >=14.0<14.4 | |
Citrix Hypervisor | ||
Linux Linux kernel | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
Nvidia Cloud Gaming | <525.60.11 | |
Nvidia Cloud Gaming | <525.60.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34676 is a vulnerability in the NVIDIA GPU Display Driver for Linux where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering.
CVE-2022-34676 has a severity value of 7.8, which is classified as high.
Nvidia Virtual Gpu versions up to and excluding 11.11, Nvidia Virtual Gpu versions between 12.0 and 13.6 (exclusive), and Nvidia Virtual Gpu versions between 14.0 and 14.4 (exclusive) are affected.
CVE-2022-34676 can be exploited by causing an out-of-bounds read in the kernel mode layer handler of the NVIDIA GPU Display Driver for Linux.
You can find more information about CVE-2022-34676 on the NVIDIA customer support website and the Gentoo security advisory.