nvidia-graphics-drivers: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095

Debian Bug report logs - #991351
nvidia-graphics-drivers: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095

version graph

Reported by: Andreas Beckmann <anbe@debian.org>

Date: Wed, 21 Jul 2021 12:42:02 UTC

Severity: serious

Tags: security, upstream

Found in versions nvidia-graphics-drivers/343.22-1, nvidia-graphics-drivers/450.51-1, nvidia-graphics-drivers/465.24.02-1, nvidia-graphics-drivers/340.24-1, nvidia-graphics-drivers/396.18-1, nvidia-graphics-drivers/455.23.04-1, nvidia-graphics-drivers/430.14-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>:
Bug#991351; Package src:nvidia-graphics-drivers. (Wed, 21 Jul 2021 12:42:03 GMT) (full text, mbox, link).


Acknowledgement sent to Andreas Beckmann <anbe@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>. (Wed, 21 Jul 2021 12:42:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Andreas Beckmann <anbe@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: nvidia-graphics-drivers: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Date: Wed, 21 Jul 2021 14:38:52 +0200
Source: nvidia-graphics-drivers
Severity: serious
Tags: security upstream
Control: clone -1 -2 -3 -4 -5 -6 -7
Control: reassign -2 src:nvidia-graphics-drivers-legacy-340xx 340.76-6
Control: retitle -2 nvidia-graphics-drivers-legacy-340xx: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: tag -2 + wontfix
Control: reassign -3 src:nvidia-graphics-drivers-legacy-390xx 390.48-4
Control: retitle -3 nvidia-graphics-drivers-legacy-390xx: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: reassign -4 src:nvidia-graphics-drivers-tesla-418 418.87.01-1
Control: retitle -4 nvidia-graphics-drivers-tesla-418: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: reassign -5 src:nvidia-graphics-drivers-tesla-440 440.64.00-1
Control: retitle -5 nvidia-graphics-drivers-tesla-440: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: tag -5 + wontfix
Control: reassign -6 src:nvidia-graphics-drivers-tesla-450 450.51.05-1
Control: retitle -6 nvidia-graphics-drivers-tesla-450: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: reassign -7 src:nvidia-graphics-drivers-tesla-460 460.32.03-1
Control: retitle -7 nvidia-graphics-drivers-tesla-460: CVE-2021-1093, CVE-2021-1094, CVE-2021-1095
Control: found -1 340.24-1
Control: found -1 343.22-1
Control: found -1 396.18-1
Control: found -1 430.14-1
Control: found -1 450.51-1
Control: found -1 455.23.04-1
Control: found -1 465.24.02-1

https://nvidia.custhelp.com/app/answers/detail/a_id/5211

CVE‑2021‑1093 	NVIDIA GPU Display Driver for Windows and Linux
contains a vulnerability in firmware where the driver contains an
assert() or similar statement that can be triggered by an attacker,
which leads to an application exit or other behavior that is more
severe than necessary, and may lead to denial of service or system
crash.

CVE‑2021‑1094 	NVIDIA GPU Display Driver for Windows and Linux
contains a vulnerability in the kernel mode layer (nvlddmkm.sys)
handler for DxgkDdiEscape where an out of bounds array access may
lead to denial of service or information disclosure.

CVE‑2021‑1095 	NVIDIA GPU Display Driver for Windows and Linux
contains a vulnerability in the kernel mode layer (nvlddmkm.sys)
handlers for all control calls with embedded parameters where
dereferencing an untrusted pointer may lead to denial of service.

Driver Branch 			CVE IDs Addressed
R470, R460, R450, R418, R390 	CVE‑2021‑1093, CVE‑2021‑1094, CVE‑2021‑1095

Andreas

Bug 991351 cloned as bugs 991352, 991353, 991354, 991355, 991356, 991357 Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:04 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/340.24-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:13 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/343.22-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:14 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/396.18-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:14 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/430.14-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:15 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/450.51-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:15 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/455.23.04-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:16 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/465.24.02-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 21 Jul 2021 12:42:16 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jul 21 16:16:42 2021; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.