7.1

CVE-2022-34677

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NvidiaGpu Display Driver SwPlatformlinux Version >= 390 < 390.157
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 470 < 470.161.03
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 510 < 510.108.03
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 515 < 515.86.01
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 525 < 525.60.11
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 450 < 450.216.04
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 470 < 470.161.03
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 510 < 510.108.03
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 515 < 515.86.01
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 525 < 525.60.11
   NvidiaTesla Version-
NvidiaCloud Gaming Version < 525.60.12
NvidiaVirtual Gpu Version < 11.11
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaVirtual Gpu Version >= 12.0 < 13.6
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaVirtual Gpu Version >= 14.0 < 14.4
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaCloud Gaming Version < 525.60.11
   LinuxLinux Kernel Version-
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.146
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
psirt@nvidia.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-681 Incorrect Conversion between Numeric Types

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.