CVE-2021-1094
published 2021-07-22CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of…
PriorityP424medium6.1CVSS 3.1
AVLACLPRLUINSUCLINAH
EPSS
0.36%
28.0th percentile
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| nvidia | gpu_display_driver | >= 418.197.02 < 418.211.00 | 418.211.00 |
| nvidia | gpu_display_driver | >= 427.33 < 427.48 | 427.48 |
| nvidia | gpu_display_driver | >= 450.119.03 < 450.142.00 | 450.142.00 |
| nvidia | gpu_display_driver | >= 452.96 < 453.10 | 453.10 |
| nvidia | gpu_display_driver | >= 460.73.01 < 460.91.03 | 460.91.03 |
| nvidia | gpu_display_driver | >= 462.31 < 462.96 | 462.96 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.1MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net/mlx5e: Fix page reclaim for dead peer hairpin
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47246 [MEDIUM] kernel: net/mlx5e: Fix page reclaim for dead peer hairpin
kernel: net/mlx5e: Fix page reclaim for dead peer hairpin
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix page reclaim for dead peer hairpin
When adding a hairpin flow, a firmware-side send queue is created for
the peer net device, which claims some host memory pages for its
internal ring buffer. If the peer net device is removed/unbound before
the hairpin flow is deleted, then the send queue is not destroyed which
leads to a stack trace on pci device remove:
[ 748.005230] mlx5_core 0000:08:00.2: wait_func:1094:(pid 12985): MANAGE_PAGES(0x108) timeout. Will cause a leak of a command resource
[ 748.005231] mlx5_core 0000:08:00.2: reclaim_pages:514:(pid 12985): failed reclaiming pages: err -110
[ 748.001835] mlx5_core 0000:08:00.2: mlx5_reclaim_root_pages:
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-07-21·CVSS 6.2
CVE-2021-1095 [MEDIUM] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in the NVIDIA graphics drivers.
It was discovered that an assert() could be triggered in the NVIDIA
graphics drivers. A local attacker could use this to cause a denial
of service. (CVE-2021-1093)
It was discovered that the NVIDIA graphics drivers permitted an
out-of-bounds array access. A local attacker could use this
to cause a denial of service or possibly expose sensitive
information. (CVE-2021-1094)
It was discovered that the NVIDIA graphics drivers contained a
vulnerability in the kernel mode layer where they did not properly
control calls with embedded parameters in some situations. A local
attacker could use this to cause a denial of service. (CVE-2021-1095)
Instructions: After a standard
Debian
CVE-2021-1094: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...
vendor_debian·2021·CVSS 6.1
CVE-2021-1094 [MEDIUM] CVE-2021-1094: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
Scope: local
bookworm: resolved (fixed in 460.91.03-1)
bullseye: resolved (fixed in 460.91.03-1)
forky: resolved (fixed in 460.91.03-1)
sid: resolved (fixed in 460.91.03-1)
trixie: resolved (fixed in 460.91.03-1)
GHSA
GHSA-f57q-wp5c-hvr2: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1094 [MEDIUM] CWE-119 GHSA-f57q-wp5c-hvr2: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
OSV
CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
osv·2021-07-22·CVSS 6.1
CVE-2021-1094 [MEDIUM] CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner
osv·2021-07-21·CVSS 5.5
CVE-2021-1093 [MEDIUM] nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulnerabilities
It was discovered that an assert() could be triggered in the NVIDIA
graphics drivers. A local attacker could use this to cause a denial
of service. (CVE-2021-1093)
It was discovered that the NVIDIA graphics drivers permitted an
out-of-bounds array access. A local attacker could use this
to cause a denial of service or possibly expose sensitive
information. (CVE-2021-1094)
It was discovered that the NVIDIA graphics drivers contained a
vulnerability in the kernel mode layer where they did not properly
control calls with embedded parameters in some situations. A local
attacker could
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5211https://security.gentoo.org/glsa/202310-02https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5211https://security.gentoo.org/glsa/202310-02
2021-07-22
Published