First published: Thu Nov 02 2023(Updated: )
NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Virtual GPU Graphics Driver | <13.9 | |
Nvidia Virtual GPU Graphics Driver | >=14.0<15.4 | |
Nvidia Virtual GPU Graphics Driver | >=16.0<16.2 | |
Microsoft Azure Stack HCI 22H2 | ||
Ubuntu | ||
Citrix Hypervisor | ||
Linux Kernel | ||
KVM (Kernel-based Virtual Machine) | ||
Microsoft Windows | ||
Red Hat Enterprise Linux | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31018 is a vulnerability in the NVIDIA GPU Driver for Windows and Linux that allows an unprivileged regular user to cause a NULL-pointer dereference, leading to a denial of service.
The affected software includes NVIDIA Virtual GPU versions up to 13.9, versions between 14.0 and 15.4, and versions between 16.0 and 16.2.
CVE-2023-31018 has a severity level of medium (6.5).
An unprivileged regular user can exploit this vulnerability by causing a NULL-pointer dereference.
To mitigate this vulnerability, users should update to the latest version of the NVIDIA GPU Driver for Windows and Linux.