First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA vGPU Software | <11.11 | |
NVIDIA vGPU Software | >=12.0<13.6 | |
NVIDIA vGPU Software | >=14.0<14.4 | |
Citrix Hypervisor | ||
Linux Kernel | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
NVIDIA Cloud Gaming | <525.60.11 | |
NVIDIA Cloud Gaming | <525.60.12 | |
NVIDIA GPU Display Driver Linux | >=510<510.108.03 | |
NVIDIA GPU Display Driver Linux | >=515<515.86.01 | |
NVIDIA GeForce | ||
NVIDIA NVS Firmware | ||
NVIDIA Quadro | ||
NVIDIA RTX | ||
NVIDIA tesla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-34684.
The severity level of CVE-2022-34684 is high with a score of 7.1.
The affected software for CVE-2022-34684 includes Nvidia Virtual Gpu (up to version 11.11), Nvidia Virtual Gpu (between versions 12.0 and 13.6), Nvidia Virtual Gpu (between versions 14.0 and 14.4), and Nvidia Gpu Display Driver (between versions 510 and 510.108.03 on Linux).
CVE-2022-34684 is a vulnerability in the NVIDIA GPU Display Driver for Linux that allows an off-by-one error, potentially leading to data tampering or information disclosure.
You can find more information about CVE-2022-34684 on the NVIDIA website at https://nvidia.custhelp.com/app/answers/detail/a_id/5415 and the Gentoo Linux Security Advisory website at https://security.gentoo.org/glsa/202310-02.