Severity
6.1MEDIUM
EPSS
0.1%
top 75.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 21

Description

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:HExploitability: 1.8 | Impact: 4.2

Affected Packages7 packages

NVDnvidia/gpu_display_driver418.197.02418.211.00+5
CVEListV5nvidia/nvidia_gpu_display_driverAll GPU Driver versions
Debiannvidia-graphics-drivers< 460.91.03-1+3
Debiannvidia-graphics-drivers-tesla-418< 418.211.00-1
Debiannvidia-graphics-drivers-tesla-450< 450.142.00-1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-f57q-wp5c-hvr2: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm2022-05-24
OSV
CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm2021-07-22
CVEList
CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm2021-07-22
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner2021-07-21

📋Vendor Advisories

3
Red Hat
kernel: net/mlx5e: Fix page reclaim for dead peer hairpin2024-05-21
Ubuntu
NVIDIA graphics drivers vulnerabilities2021-07-21
Debian
CVE-2021-1094: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...2021
CVE-2021-1094 (MEDIUM CVSS 6.1) | NVIDIA GPU Display Driver for Windo | cvebase.io