First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=390<390.157 | |
NVIDIA GPU Display Driver | >=470<470.161.03 | |
NVIDIA GPU Display Driver | >=510<510.108.03 | |
NVIDIA GPU Display Driver | >=515<515.86.01 | |
NVIDIA GPU Display Driver | >=525<525.60.11 | |
NVIDIA GeForce | ||
NVIDIA NVS Firmware | ||
NVIDIA | ||
NVIDIA RTX | ||
NVIDIA GPU Display Driver | >=450<450.216.04 | |
NVIDIA | ||
NVIDIA Cloud Gaming | <525.60.12 | |
Citrix Hypervisor | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
Nvidia Virtual GPU Graphics Driver | <11.11 | |
Nvidia Virtual GPU Graphics Driver | >=12.0<13.6 | |
Nvidia Virtual GPU Graphics Driver | >=14.0<14.4 | |
Linux Kernel | ||
VMware vSphere | ||
NVIDIA Cloud Gaming | <525.60.11 | |
Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this NVIDIA GPU Display Driver vulnerability is CVE-2022-42258.
The severity of CVE-2022-42258 is high with a CVSS score of 7.3.
The NVIDIA GPU Display Driver vulnerability affects versions 390 to 525.60.11 of the NVIDIA GPU Display Driver for Linux.
The potential impacts of CVE-2022-42258 include denial of service, data tampering, and information disclosure.
You can find more information about CVE-2022-42258 at the following references: [link1](https://lists.debian.org/debian-lts-announce/2023/05/msg00010.html), [link2](https://nvidia.custhelp.com/app/answers/detail/a_id/5415), [link3](https://security.gentoo.org/glsa/202310-02).