First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver Linux | >=390<390.157 | |
NVIDIA GPU Display Driver Linux | >=470<470.161.03 | |
NVIDIA GPU Display Driver Linux | >=510<510.108.03 | |
NVIDIA GPU Display Driver Linux | >=515<515.86.01 | |
NVIDIA GPU Display Driver Linux | >=525<525.60.11 | |
NVIDIA GeForce | ||
NVIDIA NVS Firmware | ||
NVIDIA Quadro | ||
NVIDIA RTX | ||
NVIDIA GPU Display Driver Linux | >=450<450.216.04 | |
NVIDIA tesla | ||
NVIDIA Cloud Gaming | <525.60.12 | |
Citrix Hypervisor | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
NVIDIA vGPU Software | <11.11 | |
NVIDIA vGPU Software | >=12.0<13.6 | |
NVIDIA vGPU Software | >=14.0<14.4 | |
Linux Kernel | ||
VMware vSphere | ||
NVIDIA Cloud Gaming | <525.60.11 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42257 is a vulnerability in the NVIDIA GPU Display Driver for Linux that may lead to information disclosure, data tampering, or denial of service.
The NVIDIA GPU Display Driver for Linux versions 390 and above are affected by CVE-2022-42257.
CVE-2022-42257 has a severity rating of 7.3, which is considered high.
To fix CVE-2022-42257, users should update to the latest version of the NVIDIA GPU Display Driver for Linux.
More information about CVE-2022-42257 can be found in the references provided.