nvidia-graphics-drivers: CVE-2023-31022

Related Vulnerabilities: CVE-2023-31022  

Debian Bug report logs - #1055136
nvidia-graphics-drivers: CVE-2023-31022

version graph

Reported by: Andreas Beckmann <anbe@debian.org>

Date: Wed, 1 Nov 2023 08:03:02 UTC

Severity: serious

Tags: security, upstream

Found in versions nvidia-graphics-drivers/343.22-1, nvidia-graphics-drivers/520.56.06-1, nvidia-graphics-drivers/455.23.04-1, nvidia-graphics-drivers/495.44-1, nvidia-graphics-drivers/525.53-1, nvidia-graphics-drivers/535.43.02-1, nvidia-graphics-drivers/340.24-1, nvidia-graphics-drivers/515.48.07-1, nvidia-graphics-drivers/465.24.02-1, nvidia-graphics-drivers/396.18-1, nvidia-graphics-drivers/545.23.06-1, nvidia-graphics-drivers/430.14-1, nvidia-graphics-drivers/530.30.02-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>:
Bug#1055136; Package src:nvidia-graphics-drivers. (Wed, 01 Nov 2023 08:03:04 GMT) (full text, mbox, link).


Acknowledgement sent to Andreas Beckmann <anbe@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian NVIDIA Maintainers <pkg-nvidia-devel@lists.alioth.debian.org>. (Wed, 01 Nov 2023 08:03:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Andreas Beckmann <anbe@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: nvidia-graphics-drivers: CVE-2023-31022
Date: Wed, 01 Nov 2023 09:00:10 +0100
Source: nvidia-graphics-drivers
Severity: normal
Tags: security
X-Debbugs-Cc: Debian Security Team <team@security.debian.org>
Control: clone -1 -2 -3 -4 -5 -6 -7 -8 -9
Control: reassign -2 src:nvidia-graphics-drivers-legacy-340xx 340.76-6
Control: retitle -2 nvidia-graphics-drivers-legacy-340xx: CVE-2023-31022
Control: tag -2 + wontfix
Control: reassign -3 src:nvidia-graphics-drivers-legacy-390xx 390.48-4
Control: retitle -3 nvidia-graphics-drivers-legacy-390xx: CVE-2023-31022
Control: tag -3 + wontfix
Control: reassign -4 src:nvidia-graphics-drivers-tesla-418 418.87.01-1
Control: retitle -4 nvidia-graphics-drivers-tesla-418: CVE-2023-31022
Control: tag -4 + wontfix
Control: reassign -5 src:nvidia-graphics-drivers-tesla-450 450.51.05-1
Control: retitle -5 nvidia-graphics-drivers-tesla-450: CVE-2023-31022
Control: tag -5 + wontfix
Control: reassign -6 src:nvidia-graphics-drivers-tesla-460 460.32.03-1
Control: retitle -6 nvidia-graphics-drivers-tesla-460: CVE-2023-31022
Control: tag -6 + wontfix
Control: close -6 460.106.00-3
Control: reassign -7 src:nvidia-graphics-drivers-tesla-470 470.57.02-1
Control: retitle -7 nvidia-graphics-drivers-tesla-470: CVE-2023-31022
Control: reassign -8 src:nvidia-graphics-drivers-tesla 510.85.02-1
Control: retitle -8 nvidia-graphics-drivers-tesla: CVE-2023-31022
Control: found -8 515.48.07-1
Control: found -8 525.60.13-1
Control: found -8 535.54.03-1
Control: reassign -9 src:nvidia-open-gpu-kernel-modules 515.43.04-1
Control: retitle -9 nvidia-open-gpu-kernel-modules: CVE-2023-31022
Control: found -9 520.56.06-1
Control: found -9 525.85.12-1
Control: found -9 530.30.02-1
Control: found -9 535.43.02-1
Control: found -9 545.23.06-1
Control: found -1 340.24-1
Control: found -1 343.22-1
Control: found -1 396.18-1
Control: found -1 430.14-1
Control: found -1 455.23.04-1
Control: found -1 465.24.02-1
Control: found -1 495.44-1
Control: found -1 515.48.07-1
Control: found -1 520.56.06-1
Control: found -1 525.53-1
Control: found -1 530.30.02-1
Control: found -1 535.43.02-1
Control: found -1 545.23.06-1

https://nvidia.custhelp.com/app/answers/detail/a_id/5491

CVE-2023-31022 	NVIDIA GPU Display Driver for Windows and Linux contains
a vulnerability in the kernel mode layer, where a NULL-pointer
dereference may lead to denial of service.

Linux Driver Branch 	CVE IDs Addressed
R545, R535, R525, R470 	CVE-2023-31022

Driver Branch 	Affected Driver Versions 			Updated Driver Version
R545 		All driver versions prior to 545.29.02 		545.29.02
R535 		All driver versions prior to 535.129.03 	535.129.03
R525 		All driver versions prior to 525.147.05 	525.147.05
R470 		All driver versions prior to 470.223.02 	470.223.02


Andreas



Bug 1055136 cloned as bugs 1055137, 1055138, 1055139, 1055140, 1055141, 1055142, 1055143, 1055144 Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:04 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/340.24-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:21 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/343.22-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:22 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/396.18-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:22 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/430.14-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:23 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/455.23.04-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:23 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/465.24.02-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:23 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/495.44-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:24 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/515.48.07-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:24 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/520.56.06-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:25 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/525.53-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:25 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/530.30.02-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:26 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/535.43.02-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:26 GMT) (full text, mbox, link).


Marked as found in versions nvidia-graphics-drivers/545.23.06-1. Request was from Andreas Beckmann <anbe@debian.org> to submit@bugs.debian.org. (Wed, 01 Nov 2023 08:03:27 GMT) (full text, mbox, link).


Severity set to 'serious' from 'normal' Request was from Andreas Beckmann <anbe@debian.org> to control@bugs.debian.org. (Wed, 01 Nov 2023 08:09:04 GMT) (full text, mbox, link).


Added tag(s) upstream. Request was from Andreas Beckmann <anbe@debian.org> to control@bugs.debian.org. (Wed, 01 Nov 2023 08:09:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Nov 1 17:55:08 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.