CVE-2022-42258
published 2022-12-30CVE-2022-42258: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service…
PriorityP335high7.3CVSS 3.1
AVLACLPRLUINSUCHILAH
EPSS
0.28%
19.8th percentile
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| nvidia | cloud_gaming | < 525.60.12 | 525.60.12 |
| nvidia | cloud_gaming | < 525.60.11 | 525.60.11 |
| nvidia | gpu_display_driver | >= 390 < 390.157 | 390.157 |
| nvidia | gpu_display_driver | >= 450 < 450.216.04 | 450.216.04 |
| nvidia | gpu_display_driver | >= 470 < 470.161.03 | 470.161.03 |
| nvidia | gpu_display_driver | >= 510 < 510.108.03 | 510.108.03 |
| nvidia | gpu_display_driver | >= 515 < 515.86.01 | 515.86.01 |
| nvidia | gpu_display_driver | >= 525 < 525.60.11 | 525.60.11 |
| nvidia | virtual_gpu | < 11.11 | 11.11 |
| nvidia | virtual_gpu | >= 12.0 < 13.6 | 13.6 |
| nvidia | virtual_gpu | >= 14.0 < 14.4 | 14.4 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
osv7.3HIGH
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-42258: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode ...
vendor_debian·2022·CVSS 5.3
CVE-2022-42258 [MEDIUM] CVE-2022-42258: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode ...
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.
Scope: local
bookworm: resolved (fixed in 510.108.03-1)
bullseye: resolved (fixed in 470.161.03-1)
forky: resolved (fixed in 510.108.03-1)
sid: resolved (fixed in 510.108.03-1)
trixie: resolved (fixed in 510.108.03-1)
OSV
CVE-2022-42258: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia
osv·2022-12-30·CVSS 7.3
CVE-2022-42258 [HIGH] CVE-2022-42258: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/05/msg00010.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5415https://security.gentoo.org/glsa/202310-02https://lists.debian.org/debian-lts-announce/2023/05/msg00010.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/5415https://security.gentoo.org/glsa/202310-02
2022-12-30
Published