Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

update: nvidia-drivers #1228

Closed
dongsupark opened this issue Nov 6, 2023 · 2 comments · Fixed by flatcar/scripts#2429
Closed

update: nvidia-drivers #1228

dongsupark opened this issue Nov 6, 2023 · 2 comments · Fixed by flatcar/scripts#2429
Assignees
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Nov 6, 2023

Name: nvidia-drivers
CVEs: CVE-2023-31022, CVE-2024-0074, CVE-2024-0075, CVE-2024-0078, CVE-2024-0126
CVSSs: 5.5, 7.1, 6.5, 6.5, 8.2
Action Needed: update to >= 535.216.01

Summary:

  • CVE-2023-31022: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.
  • CVE-2024-0074: NVIDIA GPU Display Driver for Linux contains a vulnerability where an attacker may access a memory location after the end of the buffer. A successful exploit of this vulnerability may lead to denial of service and data tampering.
  • CVE-2024-0075: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user may cause a NULL-pointer dereference by accessing passed parameters the validity of which has not been checked. A successful exploit of this vulnerability may lead to denial of service and limited information disclosure.
  • CVE-2024-0078: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.
  • CVE-2024-0126: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions

refmap.gentoo:

@dongsupark
Copy link
Member Author

Added CVE-2024-0074, CVE-2024-0075, CVE-2024-0078.
Needs 535.161.07.

@tormath1
Copy link
Contributor

@dongsupark dongsupark added cvss/HIGH > 7 && < 9 assessed CVSS and removed cvss/MEDIUM >= 4 && < 7 assessed CVSS labels Nov 4, 2024
@tormath1 tormath1 self-assigned this Nov 6, 2024
@tormath1 tormath1 moved this from 🪵Backlog to ⚒️ In Progress in Flatcar tactical, release planning, and roadmap Nov 6, 2024
@github-project-automation github-project-automation bot moved this from ⚒️ In Progress to Implemented in Flatcar tactical, release planning, and roadmap Nov 6, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns
Projects
Development

Successfully merging a pull request may close this issue.

2 participants