CVE-2018-6253
published 2018-04-02CVE-2018-6253: NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.7th percentile
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 390.48-1 (bookworm) | nvidia-graphics-drivers 390.48-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 390.48-1 (bookworm) | nvidia-graphics-drivers 390.48-1 (bookworm) |
| nvidia_corporation | gpu_display_driver | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2018-05-29
CVE-2018-6249 NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: NVIDIA graphics drivers could be made to crash or run programs as an
administrator.
It was discovered that the NVIDIA graphics drivers contained flaws in the
kernel mode layer. A local attacker could use these issues to cause a
denial of service or potentially escalate their privileges on the system.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2018-6253: nvidia-graphics-drivers - NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Use...
vendor_debian·2018·CVSS 5.5
CVE-2018-6253 [MEDIUM] CVE-2018-6253: nvidia-graphics-drivers - NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Use...
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.
Scope: local
bookworm: resolved (fixed in 390.48-1)
bullseye: resolved (fixed in 390.48-1)
forky: resolved (fixed in 390.48-1)
sid: resolved (fixed in 390.48-1)
trixie: resolved (fixed in 390.48-1)
GHSA
GHSA-6gwm-q2fh-qvhr: NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinit
ghsa_unreviewed·2022-05-13
CVE-2018-6253 [MEDIUM] CWE-835 GHSA-6gwm-q2fh-qvhr: NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinit
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.
OSV
CVE-2018-6253: NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinit
osv·2018-04-02·CVSS 5.5
CVE-2018-6253 [MEDIUM] CVE-2018-6253: NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinit
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities
blogs_talos·2018-03-28·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities
## Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities
Discovered by Piotr Bania of Cisco Talos
## Overview Today, Cisco Talos is disclosing multiple vulnerabilities that exist within the Nvidia D3D10 driver. This driver is used throughout multiple GPU product lines available from Nvidia. This is a commonly used driver, and exploitation can even affect VMware, thus giving rise to a potential guest-to-host escape. It is strongly recommended that patches are applied immediately.
## TALOS-2018-0514 - Nvidia D3D10 Driver Pixel Shader Heap Memory Corruption Vulnerability (CVE-2018-6251) An exploitable heap memory corruption vulnerability exists in the NVIDIA D3D10 Driver 22.21.13.8607. A specially crafted pixel shader can cause heap memory corruption, resulting
Talos
Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities
blogs_talos·2018-03-28·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities
Discovered by Piotr Bania of Cisco Talos
### OverviewToday, Cisco Talos is disclosing multiple vulnerabilities that exist within the Nvidia D3D10 driver. This driver is used throughout multiple GPU product lines available from Nvidia. This is a commonly used driver, and exploitation can even affect VMware, thus giving rise to a potential guest-to-host escape. It is strongly recommended that patches are applied immediately.
### TALOS-2018-0514 - Nvidia D3D10 Driver Pixel Shader Heap Memory Corruption Vulnerability (CVE-2018-6251)An exploitable heap memory corruption vulnerability exists in the NVIDIA D3D10 Driver 22.21.13.8607. A specially crafted pixel shader can cause heap memory corruption, resulting in at least denial of service and potential code execution. An attacker can provide a
http://nvidia.custhelp.com/app/answers/detail/a_id/4649https://usn.ubuntu.com/3662-1/https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0522http://nvidia.custhelp.com/app/answers/detail/a_id/4649https://usn.ubuntu.com/3662-1/https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0522
2018-04-02
Published