First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver Linux | >=390<390.157 | |
NVIDIA GPU Display Driver Linux | >=470<470.161.03 | |
NVIDIA GPU Display Driver Linux | >=510<510.108.03 | |
NVIDIA GPU Display Driver Linux | >=515<515.86.01 | |
NVIDIA GPU Display Driver Linux | >=525<525.60.11 | |
NVIDIA GeForce | ||
NVIDIA NVS Firmware | ||
NVIDIA Quadro | ||
NVIDIA RTX | ||
NVIDIA GPU Display Driver Linux | >=450<450.216.04 | |
NVIDIA tesla | ||
NVIDIA Cloud Gaming | <525.60.12 | |
Citrix Hypervisor | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
NVIDIA vGPU Software | <11.11 | |
NVIDIA vGPU Software | >=12.0<13.6 | |
NVIDIA vGPU Software | >=14.0<14.4 | |
Linux Kernel | ||
VMware vSphere | ||
NVIDIA Cloud Gaming | <525.60.11 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34677 is a vulnerability in the NVIDIA GPU Display Driver for Linux that allows an unprivileged user to cause denial of service or data tampering.
CVE-2022-34677 affects the kernel mode layer handler of the NVIDIA GPU Display Driver for Linux.
The severity of CVE-2022-34677 is high with a severity value of 7.1.
An unprivileged regular user can exploit CVE-2022-34677 by causing an integer to be truncated.
Yes, NVIDIA has released updates and patches to fix the vulnerability. Please refer to the references for more information.