Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: nvidia-drivers #1228

Closed
dongsupark opened this issue Nov 6, 2023 · 2 comments · Fixed by flatcar/scripts#2429
Closed

update: nvidia-drivers #1228

dongsupark opened this issue Nov 6, 2023 · 2 comments · Fixed by flatcar/scripts#2429
Assignees
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Nov 6, 2023

Name: nvidia-drivers
CVEs: CVE-2023-31022, CVE-2024-0074, CVE-2024-0075, CVE-2024-0078, CVE-2024-0126
CVSSs: 5.5, 7.1, 6.5, 6.5, 8.2
Action Needed: update to >= 535.216.01

Summary:

  • CVE-2023-31022: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.
  • CVE-2024-0074: NVIDIA GPU Display Driver for Linux contains a vulnerability where an attacker may access a memory location after the end of the buffer. A successful exploit of this vulnerability may lead to denial of service and data tampering.
  • CVE-2024-0075: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user may cause a NULL-pointer dereference by accessing passed parameters the validity of which has not been checked. A successful exploit of this vulnerability may lead to denial of service and limited information disclosure.
  • CVE-2024-0078: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.
  • CVE-2024-0126: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions

refmap.gentoo:

@dongsupark
Copy link
Member Author

Added CVE-2024-0074, CVE-2024-0075, CVE-2024-0078.
Needs 535.161.07.

@tormath1
Copy link
Contributor

@dongsupark dongsupark added cvss/HIGH > 7 && < 9 assessed CVSS and removed cvss/MEDIUM >= 4 && < 7 assessed CVSS labels Nov 4, 2024
@tormath1 tormath1 self-assigned this Nov 6, 2024
@tormath1 tormath1 moved this from 🪵Backlog to ⚒️ In Progress in Flatcar tactical, release planning, and roadmap Nov 6, 2024
@github-project-automation github-project-automation bot moved this from ⚒️ In Progress to Implemented in Flatcar tactical, release planning, and roadmap Nov 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns
Projects
Development

Successfully merging a pull request may close this issue.

2 participants