CVE-2016-7389
published 2016-11-08CVE-2016-7389: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.4th percentile
For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 367.57-1 (bookworm) | nvidia-graphics-drivers 367.57-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 367.57-1 (bookworm) | nvidia-graphics-drivers 367.57-1 (bookworm) |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x5xm-6fpv-xpgq: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304
ghsa_unreviewed·2022-05-17
CVE-2016-7389 [HIGH] GHSA-x5xm-6fpv-xpgq: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304
For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.
OSV
CVE-2016-7389: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304
osv·2016-11-08·CVSS 7.8
CVE-2016-7389 [HIGH] CVE-2016-7389: For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304
For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2016-11-03
CVE-2016-7382 NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: NVIDIA graphics drivers could be made to run programs as an administrator.
It was discovered that the NVIDIA graphics drivers incorrectly sanitized
user mode inputs. A local attacker could use this issue to possibly gain
root privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2016-7389: nvidia-graphics-drivers - For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driv...
vendor_debian·2016·CVSS 7.8
CVE-2016-7389 [HIGH] CVE-2016-7389: nvidia-graphics-drivers - For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driv...
For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.
Scope: local
bookworm: resolved (fixed in 367.57-1)
bullseye: resolved (fixed in 367.57-1)
forky: resolved (fixed in 367.57-1)
sid: resolved (fixed in 367.57-1)
trixie: resolved (fixed in 367.57-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-11-08
Published