CVE-2021-1093

CWE-4047 documents6 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 77.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 24

Description

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages13 packages

NVDnvidia/gpu_display_driver418.197.02418.211.00+5
CVEListV5nvidia/nvidia_gpu_display_driverAll GPU Driver versions
Debiannvidia-graphics-drivers< 460.91.03-1+3
Ubuntunvidia-graphics-drivers-390< 390.144-0ubuntu0.18.04.1+1
Ubuntunvidia-graphics-drivers-460< 460.91.03-0ubuntu0.18.04.1+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-9q77-p3x6-935c: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that c2022-05-24
CVEList
CVE-2021-1093: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that c2021-07-22
OSV
CVE-2021-1093: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that c2021-07-22
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner2021-07-21

📋Vendor Advisories

2
Ubuntu
NVIDIA graphics drivers vulnerabilities2021-07-21
Debian
CVE-2021-1093: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firm...2021
CVE-2021-1093 (MEDIUM CVSS 5.5) | NVIDIA GPU Display Driver for Windo | cvebase.io