CVE-2020-5963
published 2020-06-25CVE-2020-5963: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
37.7th percentile
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 440.100-1 (bookworm) | nvidia-graphics-drivers 440.100-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 440.100-1 (bookworm) | nvidia-graphics-drivers 440.100-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 440.100-1 (bookworm) | nvidia-graphics-drivers 440.100-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 440.100-1 (bookworm) | nvidia-graphics-drivers 440.100-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.15.0-108.109 | 4.15.0-108.109 |
| linux | linux_kernel | >= 0 < 5.4.0-39.43 | 5.4.0-39.43 |
| nvidia | geforce_firmware | >= 390 < 390.138 | 390.138 |
| nvidia | geforce_firmware | >= 440 < 440.100 | 440.100 |
| nvidia | geforce_firmware | >= 450 < 450.51 | 450.51 |
| nvidia | geforce_firmware | >= 450 < 451.48 | 451.48 |
| nvidia | nvidia_gpu_display_driver | — | — |
| nvidia | nvs_firmware | >= 390 < 390.138 | 390.138 |
| nvidia | nvs_firmware | >= 390 < 392.61 | 392.61 |
| nvidia | nvs_firmware | >= 418 < 426.78 | 426.78 |
| nvidia | nvs_firmware | >= 440 < 440.100 | 440.100 |
| nvidia | nvs_firmware | >= 440 < 443.18 | 443.18 |
| nvidia | nvs_firmware | >= 450 < 450.51 | 450.51 |
| nvidia | nvs_firmware | >= 450 < 451.48 | 451.48 |
| nvidia | quadro_firmware | >= 390 < 390.138 | 390.138 |
| nvidia | quadro_firmware | >= 390 < 392.61 | 392.61 |
| nvidia | quadro_firmware | >= 418 < 426.78 | 426.78 |
| nvidia | quadro_firmware | >= 440 < 440.100 | 440.100 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-25·CVSS 7.8
CVE-2020-5963 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the NVIDIA graphics driver
kernel modules.
USN-4404-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
Thomas E. Carroll discovered that the NVIDIA Cuda grpahics driver did not
properly perform access control when performing IPC. An attacker could use
this to cause a denial of service or possibly execute arbitrary code.
(CVE-2020-5963)
It was discovered that the UVM driver in the NVIDIA graphics driver
contained a race condition. A local attacker could use this to cause a
denial of service. (CVE-2020-5967)
It was discovered that the NVIDIA virtual GPU guest drivers contained
an unspe
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2020-06-25·CVSS 7.8
CVE-2020-5963 [HIGH] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
Thomas E. Carroll discovered that the NVIDIA Cuda grpahics driver did not
properly perform access control when performing IPC. An attacker could use
this to cause a denial of service or possibly execute arbitrary code.
(CVE-2020-5963)
It was discovered that the UVM driver in the NVIDIA graphics driver
contained a race condition. A local attacker could use this to cause a
denial of service. (CVE-2020-5967)
It was discovered that the NVIDIA virtual GPU guest drivers contained
an unspecified vulnerability that could potentially lead to privileged
operation execution. An attacker could use this to cause a denial of
service. (CVE-2020-5973)
Instructions: After a standard s
Debian
CVE-2020-5963: nvidia-graphics-drivers - NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the...
vendor_debian·2020·CVSS 7.8
CVE-2020-5963 [HIGH] CVE-2020-5963: nvidia-graphics-drivers - NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the...
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
Scope: local
bookworm: resolved (fixed in 440.100-1)
bullseye: resolved (fixed in 440.100-1)
forky: resolved (fixed in 440.100-1)
sid: resolved (fixed in 440.100-1)
trixie: resolved (fixed in 440.100-1)
GHSA
GHSA-3fx9-g477-r6f6: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control ma
ghsa_unreviewed·2022-05-24
CVE-2020-5963 [MEDIUM] CWE-269 GHSA-3fx9-g477-r6f6: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control ma
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
OSV
CVE-2020-5963: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control ma
osv·2020-06-25·CVSS 7.8
CVE-2020-5963 [HIGH] CVE-2020-5963: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control ma
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-440 vulnerabilities
osv·2020-06-25·CVSS 7.8
CVE-2020-5963 [HIGH] nvidia-graphics-drivers-390, nvidia-graphics-drivers-440 vulnerabilities
nvidia-graphics-drivers-390, nvidia-graphics-drivers-440 vulnerabilities
Thomas E. Carroll discovered that the NVIDIA Cuda grpahics driver did not
properly perform access control when performing IPC. An attacker could use
this to cause a denial of service or possibly execute arbitrary code.
(CVE-2020-5963)
It was discovered that the UVM driver in the NVIDIA graphics driver
contained a race condition. A local attacker could use this to cause a
denial of service. (CVE-2020-5967)
It was discovered that the NVIDIA virtual GPU guest drivers contained
an unspecified vulnerability that could potentially lead to privileged
operation execution. An attacker could use this to cause a denial of
service. (CVE-2020-5973)
OSV
linux kernel vulnerabilities
osv·2020-06-25·CVSS 7.8
CVE-2020-5963 [HIGH] linux kernel vulnerabilities
linux kernel vulnerabilities
USN-4404-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
Thomas E. Carroll discovered that the NVIDIA Cuda grpahics driver did not
properly perform access control when performing IPC. An attacker could use
this to cause a denial of service or possibly execute arbitrary code.
(CVE-2020-5963)
It was discovered that the UVM driver in the NVIDIA graphics driver
contained a race condition. A local attacker could use this to cause a
denial of service. (CVE-2020-5967)
It was discovered that the NVIDIA virtual GPU guest drivers contained
an unspecified vulnerability that could potentially lead to privileged
operation execution. An attacker co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-25
Published