5.5

CVE-2022-34680

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.

Data is provided by the National Vulnerability Database (NVD)
NvidiaGpu Display Driver SwPlatformlinux Version >= 390 < 390.157
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 470 < 470.161.03
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 510 < 510.108.03
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 515 < 515.86.01
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 525 < 525.60.11
   NvidiaGeforce Version-
   NvidiaNvs Version-
   NvidiaQuadro Version-
   NvidiaRtx Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 450 < 450.216.04
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 470 < 470.161.03
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 510 < 510.108.03
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 515 < 515.86.01
   NvidiaTesla Version-
NvidiaGpu Display Driver SwPlatformlinux Version >= 525 < 525.60.11
   NvidiaTesla Version-
NvidiaCloud Gaming Version < 525.60.12
NvidiaVirtual Gpu Version < 11.11
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaVirtual Gpu Version >= 12.0 < 13.6
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaVirtual Gpu Version >= 14.0 < 14.4
   CitrixHypervisor Version-
   LinuxLinux Kernel Version-
   RedhatEnterprise Linux Kernel-based Virtual Machine Version-
   VMwareVsphere Version-
NvidiaCloud Gaming Version < 525.60.11
   LinuxLinux Kernel Version-
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.199
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
psirt@nvidia.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-197 Numeric Truncation Error

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

CWE-681 Incorrect Conversion between Numeric Types

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.