CVE-2017-0351
Published: 9 May 2017
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.
Notes
Author | Note |
---|---|
tyhicks |
Per NVIDIA advisory, affects 375 and 381 driver branches |
Priority
Status
Package | Release | Status |
---|---|---|
nvidia-graphics-drivers
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-173
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-173-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-304
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
nvidia-graphics-drivers-304-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-310-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-319
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-319-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-331
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-331-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-340
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected)
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
nvidia-graphics-drivers-340-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-346
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-346-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-352
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-352-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-361
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-367
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
(trusty was not-affected [superseded])
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
(superseded)
|
|
yakkety |
Not vulnerable
(superseded)
|
|
zesty |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-375
Launchpad, Ubuntu, Debian |
trusty |
Released
(375.66-0ubuntu0.14.04.1)
|
upstream |
Not vulnerable
|
|
xenial |
Released
(375.66-0ubuntu0.16.04.1)
|
|
yakkety |
Released
(375.66-0ubuntu0.16.10.1)
|
|
zesty |
Released
(375.66-0ubuntu0.17.04.1)
|
|
nvidia-graphics-drivers-96
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-96-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-experimental-304
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-experimental-310
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-tegra
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
nvidia-graphics-drivers-updates
Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |