Untrusted Pointer Dereference in nVidia products - CVE-2021-1095
Published: July 20, 2021
Vulnerability identifier: #VU55040
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1095
CWE-ID: CWE-822
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: nVidia
Affected software:
NVIDIA Windows GPU Display Driver
NVIDIA Linux GPU Display Driver
NVIDIA vGPU Software
NVIDIA Windows GPU Display Driver
NVIDIA Linux GPU Display Driver
NVIDIA vGPU Software
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to untrusted pointer dereference in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters. A local user can run a specially crafted program to perform a denial of service (DoS) attack.
How to mitigate CVE-2021-1095
Install updates from vendor's website.