First published: Thu Nov 02 2023(Updated: )
NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <13.9 | |
NVIDIA Virtual GPU | >=14.0<15.4 | |
NVIDIA Virtual GPU | >=16.0<16.2 | |
Microsoft Azure Stack Hci | ||
Canonical Ubuntu Linux | ||
Citrix Hypervisor | ||
Linux Linux kernel | ||
Linux-kvm Kernel Virtual Machine | ||
Microsoft Windows | ||
Redhat Enterprise Linux | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31018 is a vulnerability in the NVIDIA GPU Driver for Windows and Linux that allows an unprivileged regular user to cause a NULL-pointer dereference, leading to a denial of service.
The affected software includes NVIDIA Virtual GPU versions up to 13.9, versions between 14.0 and 15.4, and versions between 16.0 and 16.2.
CVE-2023-31018 has a severity level of medium (6.5).
An unprivileged regular user can exploit this vulnerability by causing a NULL-pointer dereference.
To mitigate this vulnerability, users should update to the latest version of the NVIDIA GPU Driver for Windows and Linux.