CVE-2021-1052
published 2021-01-08CVE-2021-1052: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.45%
36.5th percentile
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.15.0-134.138 | 4.15.0-134.138 |
| linux | linux_kernel | >= 0 < 4.15.0-130.134 | 4.15.0-130.134 |
| linux | linux_kernel | >= 0 < 5.4.0-64.72 | 5.4.0-64.72 |
| linux | linux_kernel | >= 0 < 5.4.0-60.67 | 5.4.0-60.67 |
| nvidia | gpu_driver | >= 390 < 392.63 | 392.63 |
| nvidia | gpu_driver | >= 390 < 390.141 | 390.141 |
| nvidia | gpu_driver | >= 418 < 427.11 | 427.11 |
| nvidia | gpu_driver | >= 450 < 452.77 | 452.77 |
| nvidia | gpu_driver | >= 450 < 450.102.04 | 450.102.04 |
| nvidia | gpu_driver | >= 460 < 461.09 | 461.09 |
| nvidia | gpu_driver | >= 460 < 460.32.03 | 460.32.03 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel update
vendor_ubuntu·2021-01-21·CVSS 7.8
CVE-2021-1053 [HIGH] Linux kernel update
Title: Linux kernel update
Summary: Several security issues were fixed in NVIDIA graphics drivers.
USN-4689-3 fixed vulnerabilities in the NVIDIA server graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan L
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-01-20·CVSS 7.8
CVE-2021-1053 [HIGH] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a den
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4689-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu di
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a den
Debian
CVE-2021-1052: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulner...
vendor_debian·2021·CVSS 7.8
CVE-2021-1052 [HIGH] CVE-2021-1052: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulner...
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
Scope: local
bookworm: resolved (fixed in 460.32.03-1)
bullseye: resolved (fixed in 460.32.03-1)
forky: resolved (fixed in 460.32.03-1)
sid: resolved (fixed in 460.32.03-1)
trixie: resolved (fixed in 460.32.03-1)
GHSA
GHSA-4qmf-j7f2-r929: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1052 [HIGH] CWE-269 GHSA-4qmf-j7f2-r929: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
osv·2021-01-21·CVSS 7.8
[HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
USN-4689-3 fixed vulnerabilities in the NVIDIA server graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu disco
OSV
nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
osv·2021-01-20·CVSS 7.8
CVE-2021-1052 [HIGH] nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or possibly expose
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
osv·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
osv·2021-01-11·CVSS 7.8
[HIGH] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
USN-4689-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situatio
OSV
CVE-2021-1052: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
osv·2021-01-08·CVSS 7.8
CVE-2021-1052 [HIGH] CVE-2021-1052: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-08
Published