CVE-2022-28182
Published: 17 May 2022
NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.
Notes
Author | Note |
---|---|
sbeattie | only affects windows drivers |
mdeslaur | some binary drivers are no longer support by NVidia, so they are marked as ignored here |
Priority
Status
Package | Release | Status |
---|---|---|
nvidia-graphics-drivers-304 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Ignored
|
|
nvidia-graphics-drivers-304-updates Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-340 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Not vulnerable
(superseded)
|
|
jammy |
Not vulnerable
(superseded)
|
|
kinetic |
Not vulnerable
(superseded)
|
|
lunar |
Not vulnerable
(superseded)
|
|
mantic |
Not vulnerable
(superseded)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Ignored
|
|
nvidia-graphics-drivers-340-updates Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-352 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-352-updates Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-361 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-367 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-375 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Not vulnerable
(superseded)
|
|
nvidia-graphics-drivers-384 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Needs triage
|
|
nvidia-graphics-drivers-390 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-418-server Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-430 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Ignored
|
|
jammy |
Ignored
|
|
kinetic |
Ignored
|
|
lunar |
Ignored
|
|
mantic |
Ignored
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-435 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Ignored
|
|
jammy |
Ignored
|
|
kinetic |
Ignored
|
|
lunar |
Ignored
|
|
mantic |
Ignored
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-440 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Ignored
|
|
jammy |
Ignored
|
|
kinetic |
Ignored
|
|
lunar |
Ignored
|
|
mantic |
Ignored
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-440-server Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Ignored
|
|
jammy |
Ignored
|
|
kinetic |
Ignored
|
|
lunar |
Ignored
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-450 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Not vulnerable
(windows only)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-450-server Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-455 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
impish |
Ignored
|
|
jammy |
Ignored
|
|
kinetic |
Ignored
|
|
lunar |
Ignored
|
|
mantic |
Ignored
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-460 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Not vulnerable
(windows only)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-460-server Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-470 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Not vulnerable
(windows only)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-470-server Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Not vulnerable
(windows only)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-495 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(superseded)
|
focal |
Not vulnerable
(superseded)
|
|
impish |
Not vulnerable
(superseded)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
|
nvidia-graphics-drivers-510 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(windows only)
|
focal |
Not vulnerable
(windows only)
|
|
impish |
Not vulnerable
(windows only)
|
|
jammy |
Not vulnerable
(windows only)
|
|
kinetic |
Not vulnerable
(windows only)
|
|
lunar |
Not vulnerable
(windows only)
|
|
mantic |
Not vulnerable
(windows only)
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(windows only)
|
|
xenial |
Does not exist
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.5 |
Attack vector | Network |
Attack complexity | High |
Privileges required | Low |
User interaction | None |
Scope | Changed |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |