First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA vGPU Software | <11.11 | |
NVIDIA vGPU Software | >=12.0<13.6 | |
NVIDIA vGPU Software | >=14.0<14.4 | |
Citrix Hypervisor | ||
Linux Kernel | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
NVIDIA Cloud Gaming | <525.60.11 | |
NVIDIA Cloud Gaming | <525.60.12 | |
NVIDIA GPU Display Driver Linux | >=470<470.161.03 | |
NVIDIA GPU Display Driver Linux | >=510<510.108.03 | |
NVIDIA GPU Display Driver Linux | >=515<515.86.01 | |
NVIDIA GeForce | ||
NVIDIA NVS Firmware | ||
NVIDIA Quadro | ||
NVIDIA RTX | ||
NVIDIA GPU Display Driver Linux | >=450<450.216.04 | |
NVIDIA tesla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42264 is a vulnerability in the NVIDIA GPU Display Driver for Linux that allows an unprivileged regular user to cause data tampering, data loss, information disclosure, or denial of service.
CVE-2022-42264 affects NVIDIA Virtual GPU versions up to and exclusive to 11.11.
CVE-2022-42264 does not affect Citrix Hypervisor.
The severity of CVE-2022-42264 is high with a score of 7.8.
To fix CVE-2022-42264, update to a version of the NVIDIA GPU Display Driver for Linux that is not vulnerable.