Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2023-44216

Published: 27 September 2023

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

Notes

AuthorNote
rodrigo-zaiden
GPU.zip blog posts claims that all GPUs are likely affected
but none responded to it yet.
added nvidia drivers tracking, but later updates will
be necessary for a proper triage over nvidia and other GPUs.
mdeslaur
some binary drivers are no longer support by NVidia, so they
are marked as ignored here

Priority

Medium

Cvss 3 Severity Score

5.3

Score breakdown

Status

Package Release Status
nvidia-graphics-drivers-304
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Ignored

bionic Does not exist

focal Does not exist

jammy Does not exist

lunar Does not exist

upstream Deferred

mantic Does not exist

nvidia-graphics-drivers-304-updates
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
bionic Does not exist

focal Does not exist

jammy Does not exist

lunar Does not exist

upstream Deferred

mantic Does not exist

nvidia-graphics-drivers-340
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Ignored

focal Ignored

jammy Not vulnerable
(superseded)
lunar Not vulnerable
(superseded)
mantic Not vulnerable
(superseded)
bionic Deferred

upstream Deferred

nvidia-graphics-drivers-340-updates
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-352
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-352-updates
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-361
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-367
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-375
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Not vulnerable
(superseded)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-384
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

xenial Deferred

nvidia-graphics-drivers-390
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-418-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-430
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-435
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-440
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-440-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-450
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-450-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

mantic Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

upstream Deferred

nvidia-graphics-drivers-455
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-460
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-460-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-470
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-470-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-495
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Not vulnerable
(superseded)
jammy Does not exist

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-510
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Ignored

mantic Ignored

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-510-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Not vulnerable
(superseded)
jammy Not vulnerable
(superseded)
lunar Does not exist

upstream Not vulnerable
(superseded)
mantic Does not exist

bionic Deferred

nvidia-graphics-drivers-515
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-515-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-520
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Ignored

jammy Ignored

lunar Does not exist

mantic Does not exist

bionic Deferred

upstream Deferred

nvidia-graphics-drivers-525
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-525-server
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

upstream Deferred

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

nvidia-graphics-drivers-530
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Deferred

focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

nvidia-graphics-drivers-535
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Deferred

jammy Deferred

lunar Deferred

mantic Deferred

upstream Deferred

Severity score breakdown

Parameter Value
Base score 5.3
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N