First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <11.11 | |
NVIDIA Virtual GPU | >=12.0<13.6 | |
NVIDIA Virtual GPU | >=14.0<14.4 | |
Citrix Hypervisor | ||
Linux Linux kernel | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
Nvidia Cloud Gaming | <525.60.11 | |
Nvidia Cloud Gaming | <525.60.12 | |
Nvidia Gpu Display Driver | >=470<470.161.03 | |
Nvidia Gpu Display Driver | >=510<510.108.03 | |
Nvidia Gpu Display Driver | >=515<515.86.01 | |
Nvidia Geforce | ||
Nvidia Nvs | ||
Nvidia Quadro | ||
Nvidia Rtx | ||
Nvidia Gpu Display Driver | >=450<450.216.04 | |
Nvidia Tesla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42264 is a vulnerability in the NVIDIA GPU Display Driver for Linux that allows an unprivileged regular user to cause data tampering, data loss, information disclosure, or denial of service.
CVE-2022-42264 affects NVIDIA Virtual GPU versions up to and exclusive to 11.11.
CVE-2022-42264 does not affect Citrix Hypervisor.
The severity of CVE-2022-42264 is high with a score of 7.8.
To fix CVE-2022-42264, update to a version of the NVIDIA GPU Display Driver for Linux that is not vulnerable.