CVE-2021-1076
published 2021-04-21CVE-2021-1076: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.1th percentile
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 460.73.01-1 (bookworm) | nvidia-graphics-drivers 460.73.01-1 (bookworm) |
| nvidia | gpu_display_driver | >= 390 < 390.143 | 390.143 |
| nvidia | gpu_display_driver | >= 418 < 418.197.02 | 418.197.02 |
| nvidia | gpu_display_driver | >= 418 < 427.33 | 427.33 |
| nvidia | gpu_display_driver | >= 450 < 450.119.03 | 450.119.03 |
| nvidia | gpu_display_driver | >= 450 < 452.96 | 452.96 |
| nvidia | gpu_display_driver | >= 460 < 460.73.01 | 460.73.01 |
| nvidia | gpu_display_driver | >= 460 < 462.31 | 462.31 |
| nvidia | gpu_display_driver | >= 465 < 465.24.02 | 465.24.02 |
| nvidia | gpu_display_driver | >= 465 < 466.11 | 466.11 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_cisco7.4HIGH
vendor_debian6.6MEDIUM
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-05-04·CVSS 6.6
CVE-2021-1076 [MEDIUM] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in NVIDIA graphics drivers.
It was discovered that the NVIDIA GPU display driver for the Linux kernel
incorrectly performed access control. A local attacker could use this issue
to cause a denial of service, expose sensitive information, or escalate
privileges. (CVE-2021-1076)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
incorrectly performed reference counting. A local attacker could use this
issue to cause a denial of service. (CVE-2021-1077)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to reboot your computer to
make all the necessary changes.
Cisco
Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability
vendor_cisco·2021-02-03·CVSS 7.4
CVE-2021-1268 [HIGH] CWE-1076 Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability
Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability
A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device.
The vulnerability exists because the software incorrectly forwards IPv6 packets that have an IPv6 node-local multicast group address destination and are received on the management interfaces. An attacker could exploit this vulnerability by connecting to the same network as the management interfaces and injecting IPv6 packets that have an IPv6 node-local multicast group address destination. A successful exploit could allow the attacker to cause an IPv6 flood on the corresponding network. Depending
Debian
CVE-2021-1076: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulner...
vendor_debian·2021·CVSS 6.6
CVE-2021-1076 [MEDIUM] CVE-2021-1076: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulner...
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.
Scope: local
bookworm: resolved (fixed in 460.73.01-1)
bullseye: resolved (fixed in 460.73.01-1)
forky: resolved (fixed in 460.73.01-1)
sid: resolved (fixed in 460.73.01-1)
trixie: resolved (fixed in 460.73.01-1)
GHSA
GHSA-vfw8-mw63-c6hv: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1076 [HIGH] CWE-863 GHSA-vfw8-mw63-c6hv: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server vulner
osv·2021-05-04·CVSS 7.8
CVE-2021-1076 [HIGH] nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server vulner
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server vulnerabilities
It was discovered that the NVIDIA GPU display driver for the Linux kernel
incorrectly performed access control. A local attacker could use this issue
to cause a denial of service, expose sensitive information, or escalate
privileges. (CVE-2021-1076)
It was discovered that the NVIDIA GPU display driver for the Linux kernel
incorrectly performed reference counting. A local attacker could use this
issue to cause a denial of service. (CVE-2021-1077)
OSV
CVE-2021-1076: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
osv·2021-04-21·CVSS 7.8
CVE-2021-1076 [HIGH] CVE-2021-1076: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5172https://security.gentoo.org/glsa/202310-02https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5172https://security.gentoo.org/glsa/202310-02
2021-04-21
Published