CVE-2022-28181

Severity
9.9CRITICAL
EPSS
1.1%
top 22.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 18

Description

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages6 packages

CVEListV5nvidia/nvidia_gpu_display_driverAll GPU Driver versions for Windows and Linux
Debiannvidia-graphics-drivers< 470.129.06-5~deb11u1+3
Debiannvidia-graphics-drivers-tesla-450< 450.191.01-1~deb11u1
Debiannvidia-graphics-drivers-tesla-470< 470.129.06-1+1
Debiannvidia-graphics-drivers-legacy-390xx< 390.151-1~deb11u1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rcc4-c7gp-64w8: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network c2022-05-18
CVEList
CVE-2022-28181: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network c2022-05-17
OSV
CVE-2022-28181: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network c2022-05-17

📋Vendor Advisories

1
Debian
CVE-2022-28181: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ...2022
CVE-2022-28181 (CRITICAL CVSS 9.9) | NVIDIA GPU Display Driver for Windo | cvebase.io