7.4
CVE-2018-3979
- EPSS 0.44%
- Published 01.04.2019 21:30:43
- Last modified 21.11.2024 04:06:25
- Source talos-cna@cisco.com
- Teams watchlist Login
- Open Login
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered remotely after the user visits a malformed website. No further user interaction is required. Vulnerable versions include Ubuntu 18.04 LTS (linux 4.15.0-29-generic x86_64), Nouveau Display Driver NV117 (vermagic: 4.15.0-29-generic SMP mod_unload).
Data is provided by the National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Nvidia ≫ Geforce Gtx 745 Firmware Version-
Nvidia ≫ Geforce Gtx 750 Firmware Version-
Nvidia ≫ Geforce Gtx 750 Ti Firmware Version-
Nvidia ≫ Geforce Gtx 840m Firmware Version-
Nvidia ≫ Geforce Gtx 845m Firmware Version-
Nvidia ≫ Geforce Gtx 850m Firmware Version-
Nvidia ≫ Geforce Gtx 860m Firmware Version-
Nvidia ≫ Geforce Gtx 950m Firmware Version-
Nvidia ≫ Geforce Gtx 960m Firmware Version-
Nvidia ≫ Quadro K620 Firmware Version-
Nvidia ≫ Quadro K1200 Firmware Version-
Nvidia ≫ Quadro K2200 Firmware Version-
Nvidia ≫ Quadro M1000m Firmware Version-
Nvidia ≫ Quadro M1200m Firmware Version-
Nvidia ≫ Grid M30 Firmware Version-
Nvidia ≫ Grid M40 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.44% | 0.618 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
talos-cna@cisco.com | 7.4 | 2.8 | 4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.