PT-2015-7095 · Nvidia+2 · Nvidia Gpu Display Driver+2

Dario Weisser

·

Published

2015-09-01

·

Updated

2016-12-08

·

CVE-2015-5950

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NVIDIA display driver R352 versions prior to 353.82 NVIDIA display driver R340 versions prior to 341.81 NVIDIA display driver R304 versions prior to 304.128 NVIDIA display driver R340 versions prior to 340.93 NVIDIA display driver R352 versions prior to 352.41 NVIDIA display driver R352 versions prior to 352.46 on GRID vGPU and vSGA
Description The issue allows local users to write to an arbitrary kernel memory location, which can lead to gaining privileges via a crafted ioctl call.
Recommendations For NVIDIA display driver R352 versions prior to 353.82, update to version 353.82 or later. For NVIDIA display driver R340 versions prior to 341.81, update to version 341.81 or later. For NVIDIA display driver R304 versions prior to 304.128, update to version 304.128 or later. For NVIDIA display driver R340 versions prior to 340.93, update to version 340.93 or later. For NVIDIA display driver R352 versions prior to 352.41, update to version 352.41 or later. For NVIDIA display driver R352 versions prior to 352.46 on GRID vGPU and vSGA, update to version 352.46 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1745
ALT-PU-2015-1747
ALT-PU-2015-1835
CVE-2015-5950
MGASA-2015-0407
USN-2747-1

Affected Products

Alt Linux
Nvidia Gpu Display Driver
Ubuntu