Ubuntu update for nvidia-graphics-drivers-390



Published: 2021-07-21
Risk Low
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2021-1093
CVE-2021-1094
CVE-2021-1095
CWE-ID CWE-617
CWE-125
CWE-822
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Ubuntu
Operating systems & Components / Operating system

xserver-xorg-video-nvidia-450-server (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-460-server (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-440-server (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-390 (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-450 (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-455 (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-465 (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-460 (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-418-server (Ubuntu package)
Operating systems & Components / Operating system package or component

xserver-xorg-video-nvidia-470 (Ubuntu package)
Operating systems & Components / Operating system package or component

Vendor Canonical Ltd.

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Reachable Assertion

EUVDB-ID: #VU55038

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-1093

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion. A local user can run a specially crafted program to perform a denial of service (DoS) attack.

Mitigation

Update the affected package nvidia-graphics-drivers-390 to the latest version.

Vulnerable software versions

Ubuntu: 18.04 - 21.04

xserver-xorg-video-nvidia-450-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460-server (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-440-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-390 (Ubuntu package): before 390.144-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-450 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-455 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-465 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-418-server (Ubuntu package): before 418.211.00-0ubuntu0.20.10.1

xserver-xorg-video-nvidia-470 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

External links

http://ubuntu.com/security/notices/USN-5019-1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds read

EUVDB-ID: #VU55039

Risk: Low

CVSSv3.1: 3.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-1094

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information or perform a denial of service attack.

The vulnerability exists due to a boundary condition in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape. A local user can run a specially crafted program to trigger an out-of-bounds read and gain access to sensitive information or crash perform a DoS attack.

Mitigation

Update the affected package nvidia-graphics-drivers-390 to the latest version.

Vulnerable software versions

Ubuntu: 18.04 - 21.04

xserver-xorg-video-nvidia-450-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460-server (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-440-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-390 (Ubuntu package): before 390.144-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-450 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-455 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-465 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-418-server (Ubuntu package): before 418.211.00-0ubuntu0.20.10.1

xserver-xorg-video-nvidia-470 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

External links

http://ubuntu.com/security/notices/USN-5019-1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Untrusted Pointer Dereference

EUVDB-ID: #VU55040

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-1095

CWE-ID: CWE-822 - Untrusted Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to untrusted pointer dereference in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters. A local user can run a specially crafted program to perform a denial of service (DoS) attack.

Mitigation

Update the affected package nvidia-graphics-drivers-390 to the latest version.

Vulnerable software versions

Ubuntu: 18.04 - 21.04

xserver-xorg-video-nvidia-450-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460-server (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-440-server (Ubuntu package): before 450.142.00-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-390 (Ubuntu package): before 390.144-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-450 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-455 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-465 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-460 (Ubuntu package): before 460.91.03-0ubuntu0.21.04.1

xserver-xorg-video-nvidia-418-server (Ubuntu package): before 418.211.00-0ubuntu0.20.10.1

xserver-xorg-video-nvidia-470 (Ubuntu package): before 470.57.02-0ubuntu0.21.04.1

External links

http://ubuntu.com/security/notices/USN-5019-1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###