CVE-2014-8298
published 2014-12-10CVE-2014-8298: The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.04%
86.1th percentile
The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 340.65-1 (bookworm) | nvidia-graphics-drivers 340.65-1 (bookworm) |
| nvidia | gpu_driver | <= r21.2 | — |
| nvidia | gpu_driver | <= r39 | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2014-12-10
CVE-2014-8091 NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in the NVIDIA graphics drivers.
It was discovered that the NVIDIA graphics drivers incorrectly handled GLX
indirect rendering support. An attacker able to connect to an X server,
either locally or remotely, could use these issues to cause the X server to
crash or execute arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2014-8298: nvidia-graphics-drivers - The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R...
vendor_debian·2014·CVSS 7.5
CVE-2014-8298 [HIGH] CVE-2014-8298: nvidia-graphics-drivers - The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R...
The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.
Scope: local
bookworm: resolved (fixed in 340.65-1)
bullseye: resolved (fixed in 340.65-1)
forky: resolved (fixed in 340.65-1)
sid: resolved (fixed in 340.65-1)
trixie: resolved (fixed in 340.65-1)
GHSA
GHSA-2ph2-8m3c-5288: The NVIDIA Linux Discrete GPU drivers before R304
ghsa_unreviewed·2022-05-17
CVE-2014-8298 [HIGH] GHSA-2ph2-8m3c-5288: The NVIDIA Linux Discrete GPU drivers before R304
The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.
OSV
CVE-2014-8298: The NVIDIA Linux Discrete GPU drivers before R304
osv·2014-12-10·CVSS 7.5
CVE-2014-8298 [HIGH] CVE-2014-8298: The NVIDIA Linux Discrete GPU drivers before R304
The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-12-10
Published