CVE-2021-1056
published 2021-01-08CVE-2021-1056: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
1.78%
75.7th percentile
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 460.32.03-1 (bookworm) | nvidia-graphics-drivers 460.32.03-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.15.0-134.138 | 4.15.0-134.138 |
| linux | linux_kernel | >= 0 < 4.15.0-130.134 | 4.15.0-130.134 |
| linux | linux_kernel | >= 0 < 5.4.0-64.72 | 5.4.0-64.72 |
| linux | linux_kernel | >= 0 < 5.4.0-60.67 | 5.4.0-60.67 |
| nvidia | gpu_driver | >= 390 < 390.141 | 390.141 |
| nvidia | gpu_driver | >= 450 < 450.102.04 | 450.102.04 |
| nvidia | gpu_driver | >= 460 < 460.32.03 | 460.32.03 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel update
vendor_ubuntu·2021-01-21·CVSS 7.8
CVE-2021-1053 [HIGH] Linux kernel update
Title: Linux kernel update
Summary: Several security issues were fixed in NVIDIA graphics drivers.
USN-4689-3 fixed vulnerabilities in the NVIDIA server graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan L
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-01-20·CVSS 7.8
CVE-2021-1053 [HIGH] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a den
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4689-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu di
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a den
Debian
CVE-2021-1056: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in t...
vendor_debian·2021·CVSS 7.1
CVE-2021-1056 [HIGH] CVE-2021-1056: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in t...
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
Scope: local
bookworm: resolved (fixed in 460.32.03-1)
bullseye: resolved (fixed in 460.32.03-1)
forky: resolved (fixed in 460.32.03-1)
sid: resolved (fixed in 460.32.03-1)
trixie: resolved (fixed in 460.32.03-1)
GHSA
GHSA-f8fj-4gwg-crcc: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia
ghsa_unreviewed·2022-05-24
CVE-2021-1056 [HIGH] CWE-276 GHSA-f8fj-4gwg-crcc: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
osv·2021-01-21·CVSS 7.8
[HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update
USN-4689-3 fixed vulnerabilities in the NVIDIA server graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu disco
OSV
nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
osv·2021-01-20·CVSS 7.8
CVE-2021-1052 [HIGH] nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server vulnerabilities
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or possibly expose
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
osv·2021-01-11·CVSS 7.8
CVE-2021-1052 [HIGH] nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
osv·2021-01-11·CVSS 7.8
[HIGH] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities
USN-4689-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.
Original advisory details:
It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situatio
OSV
CVE-2021-1056: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia
osv·2021-01-08·CVSS 7.1
CVE-2021-1056 [HIGH] CVE-2021-1056: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5142https://security.gentoo.org/glsa/202310-02https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5142https://security.gentoo.org/glsa/202310-02
2021-01-08
Published