First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <11.11 | |
NVIDIA Virtual GPU | >=12.0<13.6 | |
NVIDIA Virtual GPU | >=14.0<14.4 | |
Citrix Hypervisor | ||
Linux Linux kernel | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
Nvidia Cloud Gaming | <525.60.11 | |
Nvidia Cloud Gaming | <525.60.12 | |
Nvidia Gpu Display Driver | >=470<470.161.03 | |
Nvidia Gpu Display Driver | >=510<510.108.03 | |
Nvidia Gpu Display Driver | >=515<515.86.01 | |
Nvidia Geforce | ||
Nvidia Nvs | ||
Nvidia Quadro | ||
Nvidia Rtx | ||
Nvidia Tesla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42254.
The severity level of CVE-2022-42254 is high.
The affected software for CVE-2022-42254 includes Nvidia Virtual Gpu, Nvidia Cloud Gaming, and Nvidia Gpu Display Driver for Linux.
CVE-2022-42254 can be exploited by an attacker through an out-of-bounds array access in the kernel mode layer of the Nvidia GPU Display Driver for Linux, leading to denial of service, data tampering, or information disclosure.
No, Citrix Hypervisor, Linux Linux kernel, Redhat Enterprise Linux Kernel-based Virtual Machine, Vmware Vsphere, Nvidia Geforce, Nvidia Nvs, Nvidia Quadro, Nvidia Rtx, and Nvidia Tesla are not affected by CVE-2022-42254.