#VU55039 Out-of-bounds read in nVidia products - CVE-2021-1094
Published: July 20, 2021
NVIDIA Windows GPU Display Driver
NVIDIA Linux GPU Display Driver
NVIDIA vGPU Software
nVidia
Description
The vulnerability allows a local user to gain access to potentially sensitive information or perform a denial of service attack.
The vulnerability exists due to a boundary condition in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape. A local user can run a specially crafted program to trigger an out-of-bounds read and gain access to sensitive information or crash perform a DoS attack.