USN-4404-2: Linux kernel vulnerabilities

25 June 2020

Several security issues were fixed in the NVIDIA graphics driver kernel modules.

Releases

Packages

Details

USN-4404-1 fixed vulnerabilities in the NVIDIA graphics drivers.
This update provides the corresponding updates for the NVIDIA Linux
DKMS kernel modules.

Original advisory details:

Thomas E. Carroll discovered that the NVIDIA Cuda grpahics driver did not
properly perform access control when performing IPC. An attacker could use
this to cause a denial of service or possibly execute arbitrary code.
(CVE-2020-5963)

It was discovered that the UVM driver in the NVIDIA graphics driver
contained a race condition. A local attacker could use this to cause a
denial of service. (CVE-2020-5967)

It was discovered that the NVIDIA virtual GPU guest drivers contained
an unspecified vulnerability that could potentially lead to privileged
operation execution. An attacker could use this to cause a denial of
service. (CVE-2020-5973)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04
Ubuntu 19.10
Ubuntu 18.04

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

Related notices

  • USN-4404-1: nvidia-utils-430, libnvidia-encode-430, nvidia-dkms-390, nvidia-dkms-440, libnvidia-common-430, nvidia-utils-390, nvidia-opencl-icd-384, libnvidia-fbc1-430, libnvidia-gl-390, nvidia-384, nvidia-headless-440, nvidia-kernel-source-430, libnvidia-cfg1-440, libnvidia-ifr1-390, nvidia-kernel-common-440, libnvidia-fbc1-440, libnvidia-gl-430, nvidia-kernel-common-390, nvidia-compute-utils-440, nvidia-utils-440, nvidia-kernel-common-430, nvidia-headless-no-dkms-440, libnvidia-decode-430, nvidia-driver-430, nvidia-graphics-drivers-440, libnvidia-ifr1-440, libnvidia-common-390, libcuda1-384, nvidia-graphics-drivers-390, libnvidia-cfg1-390, libnvidia-cfg1-430, nvidia-headless-no-dkms-430, libnvidia-compute-390, nvidia-headless-430, xserver-xorg-video-nvidia-430, nvidia-driver-440, nvidia-kernel-source-440, libnvidia-compute-440, nvidia-kernel-source-390, libnvidia-extra-440, libnvidia-encode-440, libnvidia-ifr1-430, nvidia-dkms-430, libnvidia-gl-440, libnvidia-encode-390, xserver-xorg-video-nvidia-440, libnvidia-decode-390, libnvidia-compute-430, nvidia-headless-no-dkms-390, nvidia-384-dev, nvidia-driver-390, libnvidia-decode-440, nvidia-compute-utils-390, nvidia-libopencl1-384, xserver-xorg-video-nvidia-390, libnvidia-common-440, libnvidia-fbc1-390, nvidia-headless-390, nvidia-compute-utils-430