CVE-2023-0189
published 2023-04-01CVE-2023-0189: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.2th percentile
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers 525.105.17-1 (bookworm) | nvidia-graphics-drivers 525.105.17-1 (bookworm) |
| nvidia | virtual_gpu | < 11.12 | 11.12 |
| nvidia | virtual_gpu | >= 13.0 < 13.7 | 13.7 |
| nvidia | virtual_gpu | >= 15.0 < 15.2 | 15.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2ff5-j2jm-mwcq: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, esc
ghsa_unreviewed·2023-04-01
CVE-2023-0189 [HIGH] CWE-822 GHSA-2ff5-j2jm-mwcq: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, esc
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
OSV
CVE-2023-0189: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, esc
osv·2023-04-01·CVSS 7.8
CVE-2023-0189 [HIGH] CVE-2023-0189: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, esc
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Debian
CVE-2023-0189: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode ...
vendor_debian·2023·CVSS 8.8
CVE-2023-0189 [HIGH] CVE-2023-0189: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode ...
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Scope: local
bookworm: resolved (fixed in 525.105.17-1)
bullseye: resolved (fixed in 470.182.03-1)
forky: resolved (fixed in 525.105.17-1)
sid: resolved (fixed in 525.105.17-1)
trixie: resolved (fixed in 525.105.17-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-2191 jetty-server: Improper release of ByteBuffers in SslConnections
bugzilla·2022-08-09·CVSS 7.5
CVE-2022-2191 [HIGH] CVE-2022-2191 jetty-server: Improper release of ByteBuffers in SslConnections
CVE-2022-2191 jetty-server: Improper release of ByteBuffers in SslConnections
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
Discussion:
Based on https://github.com/eclipse/jetty.project/issues/8161#issuecomment-1178728623 this issue is not affecting jetty 9.4.x versions.
---
This issue has been addressed in the following products:
Red Hat AMQ Streams 2.3.0
Via RHSA-2023:0189 https://access.redhat.com/errata/RHSA-2023:0189
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2022-2191
Bugzilla
CVE-2022-2047 jetty-http: improver hostname input handling
bugzilla·2022-08-09·CVSS 2.7
CVE-2022-2047 [LOW] CVE-2022-2047 jetty-http: improver hostname input handling
CVE-2022-2047 jetty-http: improver hostname input handling
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
References:
https://github.com/eclipse/jetty.project/security/advisories/GHSA-cj7v-27pg-wf7q
Discussion:
This issue has been addressed in the following products:
Red Hat AMQ Streams 2.3.0
Via RHSA-2023:0189 https://access.redhat.com/errata/RHSA-2023:0189
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2022-2047
---
This issue has been addresse
2023-04-01
Published