CVE-2017-0350
Published: 9 May 2017
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
Notes
Author | Note |
---|---|
tyhicks | Per NVIDIA advisory, affects 375 and 381 driver branches |
Priority
Status
Package | Release | Status |
---|---|---|
nvidia-graphics-drivers Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-173 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-173-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-304 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
nvidia-graphics-drivers-304-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-310-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-319 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-319-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-331 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-331-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-340 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
nvidia-graphics-drivers-340-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-346 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-346-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-352 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-352-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-361 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-367 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-375 Launchpad, Ubuntu, Debian |
trusty |
Released
(375.66-0ubuntu0.14.04.1)
|
upstream |
Not vulnerable
|
|
xenial |
Released
(375.66-0ubuntu0.16.04.1)
|
|
yakkety |
Released
(375.66-0ubuntu0.16.10.1)
|
|
zesty |
Released
(375.66-0ubuntu0.17.04.1)
|
|
nvidia-graphics-drivers-96 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-96-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-experimental-304 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-experimental-310 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-tegra Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-updates Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |