CVE-2021-1095
published 2021-07-22CVE-2021-1095: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.6th percentile
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 460.91.03-1 (bookworm) | nvidia-graphics-drivers 460.91.03-1 (bookworm) |
| nvidia | gpu_display_driver | >= 418.197.02 < 418.211.00 | 418.211.00 |
| nvidia | gpu_display_driver | >= 427.33 < 427.48 | 427.48 |
| nvidia | gpu_display_driver | >= 450.119.03 < 450.142.00 | 450.142.00 |
| nvidia | gpu_display_driver | >= 452.96 < 453.10 | 453.10 |
| nvidia | gpu_display_driver | >= 460.73.01 < 460.91.03 | 460.91.03 |
| nvidia | gpu_display_driver | >= 462.31 < 462.96 | 462.96 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h2cm-gjfc-694c: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1095 [MEDIUM] CWE-476 GHSA-h2cm-gjfc-694c: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
OSV
CVE-2021-1095: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
osv·2021-07-22·CVSS 5.5
CVE-2021-1095 [MEDIUM] CVE-2021-1095: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
OSV
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner
osv·2021-07-21·CVSS 5.5
CVE-2021-1093 [MEDIUM] nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulner
nvidia-graphics-drivers-390, nvidia-graphics-drivers-418-server, nvidia-graphics-drivers-450-server, nvidia-graphics-drivers-460, nvidia-graphics-drivers-460-server, nvidia-graphics-drivers-470 vulnerabilities
It was discovered that an assert() could be triggered in the NVIDIA
graphics drivers. A local attacker could use this to cause a denial
of service. (CVE-2021-1093)
It was discovered that the NVIDIA graphics drivers permitted an
out-of-bounds array access. A local attacker could use this
to cause a denial of service or possibly expose sensitive
information. (CVE-2021-1094)
It was discovered that the NVIDIA graphics drivers contained a
vulnerability in the kernel mode layer where they did not properly
control calls with embedded parameters in some situations. A local
attacker could
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2021-07-21·CVSS 6.2
CVE-2021-1095 [MEDIUM] NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: Several security issues were fixed in the NVIDIA graphics drivers.
It was discovered that an assert() could be triggered in the NVIDIA
graphics drivers. A local attacker could use this to cause a denial
of service. (CVE-2021-1093)
It was discovered that the NVIDIA graphics drivers permitted an
out-of-bounds array access. A local attacker could use this
to cause a denial of service or possibly expose sensitive
information. (CVE-2021-1094)
It was discovered that the NVIDIA graphics drivers contained a
vulnerability in the kernel mode layer where they did not properly
control calls with embedded parameters in some situations. A local
attacker could use this to cause a denial of service. (CVE-2021-1095)
Instructions: After a standard
Debian
CVE-2021-1095: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...
vendor_debian·2021·CVSS 5.5
CVE-2021-1095 [MEDIUM] CVE-2021-1095: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
Scope: local
bookworm: resolved (fixed in 460.91.03-1)
bullseye: resolved (fixed in 460.91.03-1)
forky: resolved (fixed in 460.91.03-1)
sid: resolved (fixed in 460.91.03-1)
trixie: resolved (fixed in 460.91.03-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5211https://security.gentoo.org/glsa/202310-02https://lists.debian.org/debian-lts-announce/2022/01/msg00013.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5211https://security.gentoo.org/glsa/202310-02
2021-07-22
Published