CERT-In Vulnerability Note
CIVN-2022-0247
Multiple vulnerabilities in NVIDIA GPU Display Driver
Original Issue Date:May 25, 2022
Severity Rating: HIGH
Systems Affected
- NVIDIA GeForce Driver R510 (All versions prior to 512.77) for windows
- NVIDIA Studio Driver R510 (All versions ) for windows
- NVIDIA RTX/Quadro, NVS Driver R510 (All versions prior to 512.78) for windows
- NVIDIA RTX/Quadro, NVS Driver R470 (All versions prior to 473.47) for windows
- NVIDIA Tesla Driver R510 (All versions ) for windows
- NVIDIA Tesla Driver R470 (All versions prior to 473.47) for windows
- NVIDIA Tesla Driver R450 (All versions prior to 453.51) for windows
- GeForce, NVIDIA RTX/Quadro, NVS Driver R510 (All versions prior to 510.73.05) for Linux
- GeForce, NVIDIA RTX/Quadro, NVS Driver R470 (All versions prior to 470.129.06) for Linux
- GeForce, NVIDIA RTX/Quadro, NVS Driver R390 (All versions prior to 390.151) for Linux
- NVIDIA TeslaDriver R510 (All versions ) for Linux
- NVIDIA TeslaDriver R470 (All versions prior to 470.129.06 ) for Linux
- NVIDIA TeslaDriver R450 (All versions prior to 450.191.01 ) for Linux
- NVIDIA vGPU software (guest driver) Driver 511.65 (All versions prior to and including 14.0) for Windows
- NVIDIA vGPU software (guest driver) Driver 472.98 (All versions prior to and including 13.2) for Windows
- NVIDIA vGPU software (guest driver) Driver 453.37 (All versions prior to and including 11.7) for Windows
- NVIDIA vGPU software (guest driver) Driver 510.47.03 (All versions prior to and including 14.0) for Linux
- NVIDIA vGPU software (guest driver) Driver 470.103.01 (All versions prior to and including 13.2) for Linux
- NVIDIA vGPU software (guest driver) Driver 450.172.01 (All versions prior to and including 11.7) for Linux
- NVIDIA vGPU software (guest driver) Driver 510.47.03 (All versions prior to and including 14.0) for Citrix Hypervisor,VMware vSphere and Red Hat Enterprise Linux KVM
- NVIDIA vGPU software (guest driver) Driver 470.103.02 (All versions prior to and including 13.2) for Citrix Hypervisor,VMware vSphere and Red Hat Enterprise Linux KVM
- NVIDIA vGPU software (guest driver) Driver 450.172 (All versions prior to and including 11.7) for Citrix Hypervisor,VMware vSphere and Red Hat Enterprise Linux KVM
- NVIDIA Cloud Gaming Guest Driver 512.59 (All versions prior to and including the April 2022 Cloud Gaming Release)for Windows
- NVIDIA Cloud Gaming Guest Driver 510.68.02 (All versions prior to and including the April 2022 Cloud Gaming Release)for Linux
- NVIDIA Cloud Gaming Virtual GPU Manager Driver 510.68.02 (All versions prior to and including the April 2022 Cloud Gaming Release)for Citrix Hypervisor and Red Hat Enterprise Linux with KVM
Overview
Multiple vulnerabilities have been reported in NVIDIA GPU Display Driver and NVIDIA vGPU software which could allow an attacker to gain elevated privileges, execute arbitrary code, data tampering, disclose sensitive information and cause denial of service condition on the targeted System.
Description
These vulnerabilities exist in NVIDIA GPU Display Driver for windows and Linux , NVIDIA vGPU software in the guest driver and virtual GPU manager, and NVIDIA CLOUD GAMING in the guest driver and virtual GPU manager due to out-of-bounds write in the kernel mode layer and ECC layer, improper input validation in kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, improper memory management in the kernel mode layer (nvlddmkm.sys), NULL pointer dereference in in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, use-after-free and uncontrolled resource consumption in the Virtual GPU Manager (nvidia.ko).
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges, execute arbitrary code, data tampering, disclose sensitive information and cause denial of service condition on the targeted System.
Solution
Upgrade to latest version as mentioned
https://nvidia.custhelp.com/app/answers/detail/a_id/5353
Vendor Information
NVIDIA
https://nvidia.custhelp.com/app/answers/detail/a_id/5353
References
NVIDIA
https://nvidia.custhelp.com/app/answers/detail/a_id/5353
CVE Name
CVE-2022-28181
CVE-2022-28182
CVE-2022-28183
CVE-2022-28184
CVE-2022-28185
CVE-2022-28186
CVE-2022-28187
CVE-2022-28188
CVE-2022-28189
CVE-2022-28190
CVE-2022-28191
CVE-2022-28192
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|