CVE-2016-7382

CWE-2756 documents6 sources
Severity
7.8HIGH
EPSS
0.0%
top 85.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 8
Latest updateMay 17

Description

For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) handler where a missing permissions check may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debiannvidia-graphics-drivers< 367.57-1+3
NVDnvidia/gpu_driver6 versions+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mv66-58mr-wjh5: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm2022-05-17
OSV
CVE-2016-7382: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm2016-11-08
CVEList
CVE-2016-7382: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm2016-11-08

📋Vendor Advisories

2
Ubuntu
NVIDIA graphics drivers vulnerabilities2016-11-03
Debian
CVE-2016-7382: nvidia-graphics-drivers - For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driv...2016
CVE-2016-7382 (HIGH CVSS 7.8) | For the NVIDIA Quadro | cvebase.io