PT-2015-7095 · Nvidia+2 · Nvidia Gpu Display Driver+2
Dario Weisser
·
Published
2015-09-01
·
Updated
2016-12-08
·
CVE-2015-5950
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NVIDIA display driver R352 versions prior to 353.82
NVIDIA display driver R340 versions prior to 341.81
NVIDIA display driver R304 versions prior to 304.128
NVIDIA display driver R340 versions prior to 340.93
NVIDIA display driver R352 versions prior to 352.41
NVIDIA display driver R352 versions prior to 352.46 on GRID vGPU and vSGA
Description
The issue allows local users to write to an arbitrary kernel memory location, which can lead to gaining privileges via a crafted ioctl call.
Recommendations
For NVIDIA display driver R352 versions prior to 353.82, update to version 353.82 or later.
For NVIDIA display driver R340 versions prior to 341.81, update to version 341.81 or later.
For NVIDIA display driver R304 versions prior to 304.128, update to version 304.128 or later.
For NVIDIA display driver R340 versions prior to 340.93, update to version 340.93 or later.
For NVIDIA display driver R352 versions prior to 352.41, update to version 352.41 or later.
For NVIDIA display driver R352 versions prior to 352.46 on GRID vGPU and vSGA, update to version 352.46 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Nvidia Gpu Display Driver
Ubuntu