nvidia-graphics-drivers: CVE-2021-1076, CVE-2021-1077

Related Vulnerabilities: CVE-2021-1076   CVE-2021-1077   CVE‑2021‑1076   CVE‑2021‑1077  

Debian Bug report logs - #987216
nvidia-graphics-drivers: CVE-2021-1076, CVE-2021-1077

version graph

Reported by: Andreas Beckmann <anbe@debian.org>

Date: Mon, 19 Apr 2021 20:06:01 UTC

Severity: serious

Tags: security, upstream

Found in versions nvidia-graphics-drivers/455.23.04-1, nvidia-graphics-drivers/450.51-1, nvidia-graphics-drivers/430.14-1, nvidia-graphics-drivers/340.24-1, nvidia-graphics-drivers/396.18-1, nvidia-graphics-drivers/343.22-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>:
Bug#987216; Package src:nvidia-graphics-drivers. (Mon, 19 Apr 2021 20:06:03 GMT) (full text, mbox, link).


Acknowledgement sent to Andreas Beckmann <anbe@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>. (Mon, 19 Apr 2021 20:06:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Andreas Beckmann <anbe@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: nvidia-graphics-drivers: CVE-2021-1076, CVE-2021-1077
Date: Mon, 19 Apr 2021 22:04:10 +0200
Source: nvidia-graphics-drivers
Severity: serious
Tags: security upstream
Control: clone -1 -2 -3 -4 -5 -6 -7
Control: reassign -2 src:nvidia-graphics-drivers-legacy-340xx 340.76-6
Control: retitle -2 nvidia-graphics-drivers-legacy-340xx: CVE-2021-1076
Control: tag -2 + wontfix
Control: reassign -3 src:nvidia-graphics-drivers-legacy-390xx 390.48-4
Control: retitle -3 nvidia-graphics-drivers-legacy-390xx: CVE-2021-1076
Control: reassign -4 src:nvidia-graphics-drivers-tesla-418 418.87.01-1
Control: retitle -4 nvidia-graphics-drivers-tesla-418: CVE-2021-1076
Control: reassign -5 src:nvidia-graphics-drivers-tesla-440 440.64.00-1
Control: retitle -5 nvidia-graphics-drivers-tesla-440: CVE-2021-1076
Control: tag -5 + wontfix
Control: reassign -6 src:nvidia-graphics-drivers-tesla-450 450.51.05-1
Control: retitle -6 nvidia-graphics-drivers-tesla-450: CVE-2021-1076, CVE-2021-1077
Control: reassign -7 src:nvidia-graphics-drivers-tesla-460 460.32.03-1
Control: retitle -7 nvidia-graphics-drivers-tesla-460: CVE-2021-1076, CVE-2021-1077
Control: found -1 340.24-1
Control: found -1 343.22-1
Control: found -1 396.18-1
Control: found -1 430.14-1
Control: found -1 450.51-1
Control: found -1 455.23.04-1

https://nvidia.custhelp.com/app/answers/detail/a_id/5172

CVE‑2021‑1076 	NVIDIA GPU Display Driver for Windows and Linux
contains a vulnerability in the kernel mode layer (nvlddmkm.sys or
nvidia.ko) where improper access control may lead to denial of
service, information disclosure, or data corruption.

CVE‑2021‑1077 	NVIDIA GPU Display Driver for Windows and Linux
contains a vulnerability where the software uses a reference count to
manage a resource that is incorrectly updated, which may lead to
denial of service.

Driver Branch 		CVE IDs Addressed
R465, R418, R390 	CVE‑2021‑1076
R460, R450 		CVE‑2021‑1076, CVE‑2021‑1077

Andreas

Bug 987216 cloned as bugs 987217, 987218, 987219, 987220, 987221, 987222 Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:03 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/340.24-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:12 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/343.22-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:13 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/396.18-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:13 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/430.14-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:13 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/450.51-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:14 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/455.23.04-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Mon, 19 Apr 2021 20:06:14 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Tue Apr 20 08:07:12 2021; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.